Generate cryptographically strong .env secrets

Hex, base64 or URL-safe, in any quantity. Backed by the Web Crypto API, ready to paste straight into your .env.

Free tool · Updated August 2026 · No account required

Generate secrets
Web Crypto · 100% local
.env

Choose your options and generate a fresh set.

What makes a secure API key?

A secure secret needs at least 128 bits of entropy, and the source matters more than the length. This generator uses crypto.getRandomValues, the same cryptographically secure source browsers use for TLS, so the keys stay unpredictable no matter how many you create.

Avoid building keys with Math.random or a date-based scheme. A short or predictable key can be guessed in seconds, while a 256-bit random key would take longer than the age of the universe to brute force.

  • At least 128 bits of entropy, with 256 available
  • A cryptographically secure random source, never Math.random
  • One format per service so values stay URL-safe where needed

Hex, base64 or URL-safe: which format to choose

Hex is the safest default: it is case-insensitive, works everywhere and is easy to paste. Base64 packs more entropy into fewer characters, which matters when a provider limits key length. URL-safe base64 replaces the + and / characters so the key never breaks a query string.

Pick hex for general .env secrets, URL-safe base64 for keys that travel inside URLs, and plain base64 when a provider specifies it. Generate any of them here in batches of up to 50 with one click, then lock the file with the vault encryptor before committing.

Frequently Asked Questions

Common questions about generating .env secrets

Yes. Every secret comes from crypto.getRandomValues, the browser's hardware-backed CSPRNG. No Math.random and no weak PRNG.