TechWeirdoTools

Options

256 bits of entropy per value

Common lengths

Random values

Ready.

Handle secrets carefully

Store generated keys in a secret manager or environment variable — never in source control, logs or client-side code.

How to generate a random hex string

  1. Pick the byte length

    Each byte becomes two hex characters. 32 bytes gives a 64-character string with 256 bits of entropy.

  2. Choose how many and the format

    Generate up to 100 values. Switch to uppercase, add a 0x prefix, or output the same random bytes as Base64 or Base64URL.

  3. Copy a value

    Copy one row or the whole list. Every click creates a fresh batch; nothing is stored.

How many bytes do you need?

Hexadecimal is just a readable encoding of bytes: it doesn’t add or remove randomness. Choose the length by the security level you need, then encode it however your system expects.

Use caseBytesHex lengthEntropy
AES-GCM nonce / IV122496 bits
Session ID, CSRF token, salt1632128 bits
API key, password-reset token3264256 bits
AES-256 key, HMAC-SHA256 secret, JWT HS256 secret3264256 bits
HMAC-SHA512 secret64128512 bits

Equivalent commands

The values here are generated the same way as these standard commands — useful when you need to script it:

openssl rand -hex 32
python3 -c "import secrets; print(secrets.token_hex(32))"
node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"

Is this really random?

Yes. Every byte comes from crypto.getRandomValues(), the browser’s cryptographically secure random number generator, which is seeded by the operating system. It is not Math.random(), which is predictable and must never be used for secrets.

Frequently asked questions

Is this random hex generator cryptographically secure?

Yes. Every value comes from the Web Crypto getRandomValues() API, not Math.random(). The values are created on your device and never sent anywhere.

How many hex characters does one byte create?

Two. A 32-byte value is 64 hexadecimal characters long, or 66 with the 0x prefix.

How long should a secret key be?

32 bytes (256 bits) is a strong default for API keys, HMAC-SHA256 secrets, JWT HS256 secrets and AES-256 keys. 16 bytes (128 bits) is enough for unguessable identifiers like session IDs and CSRF tokens.

What’s the difference between the hex and Base64 output?

Both encode the same random bytes. Hex uses 2 characters per byte; Base64 uses about 1.33, so it is shorter. Base64URL swaps + and / for - and _ and drops padding, which makes it safe in URLs and filenames.