What makes a secure API key?
A secure secret needs at least 128 bits of entropy, and the source matters more than the length. This generator uses crypto.getRandomValues, the same cryptographically secure source browsers use for TLS, so the keys stay unpredictable no matter how many you create.
Avoid building keys with Math.random or a date-based scheme. A short or predictable key can be guessed in seconds, while a 256-bit random key would take longer than the age of the universe to brute force.
- At least 128 bits of entropy, with 256 available
- A cryptographically secure random source, never
Math.random - One format per service so values stay URL-safe where needed