Random Hex Generator
Create cryptographically secure hexadecimal strings by exact byte length — for secret keys, API tokens, nonces, salts and test data. Generate one or a hundred at once.
How to generate a random hex string
Pick the byte length
Each byte becomes two hex characters. 32 bytes gives a 64-character string with 256 bits of entropy.
Choose how many and the format
Generate up to 100 values. Switch to uppercase, add a
0xprefix, or output the same random bytes as Base64 or Base64URL.Copy a value
Copy one row or the whole list. Every click creates a fresh batch; nothing is stored.
How many bytes do you need?
Hexadecimal is just a readable encoding of bytes: it doesn’t add or remove randomness. Choose the length by the security level you need, then encode it however your system expects.
| Use case | Bytes | Hex length | Entropy |
|---|---|---|---|
| AES-GCM nonce / IV | 12 | 24 | 96 bits |
| Session ID, CSRF token, salt | 16 | 32 | 128 bits |
| API key, password-reset token | 32 | 64 | 256 bits |
| AES-256 key, HMAC-SHA256 secret, JWT HS256 secret | 32 | 64 | 256 bits |
| HMAC-SHA512 secret | 64 | 128 | 512 bits |
Equivalent commands
The values here are generated the same way as these standard commands — useful when you need to script it:
openssl rand -hex 32
python3 -c "import secrets; print(secrets.token_hex(32))"
node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"Is this really random?
Yes. Every byte comes from crypto.getRandomValues(), the browser’s cryptographically secure random number generator, which is seeded by the operating system. It is not Math.random(), which is predictable and must never be used for secrets.
Frequently asked questions
Is this random hex generator cryptographically secure?
Yes. Every value comes from the Web Crypto getRandomValues() API, not Math.random(). The values are created on your device and never sent anywhere.
How many hex characters does one byte create?
Two. A 32-byte value is 64 hexadecimal characters long, or 66 with the 0x prefix.
How long should a secret key be?
32 bytes (256 bits) is a strong default for API keys, HMAC-SHA256 secrets, JWT HS256 secrets and AES-256 keys. 16 bytes (128 bits) is enough for unguessable identifiers like session IDs and CSRF tokens.
What’s the difference between the hex and Base64 output?
Both encode the same random bytes. Hex uses 2 characters per byte; Base64 uses about 1.33, so it is shorter. Base64URL swaps + and / for - and _ and drops padding, which makes it safe in URLs and filenames.