Free online tools to generate, calculate,
convert, format, encode, and play.
 

Encryption Key Generator

Generate cryptographically secure encryption keys for symmetric ciphers like AES, HMAC, and ChaCha20. All keys are generated locally in your browser using the crypto.getRandomValues() API.


Click "Generate" to create a key
Options
Enter the number of bytes (1 - 1024).
Key Info
Algorithm AES-256
Key Size 256 bits
Bytes 32
Entropy 256 bits
Brute Force (10B/s) Centuries+
Quick Reference
  • AES-128: 128-bit key, fast, widely supported
  • AES-256: 256-bit key, standard for high security
  • HMAC-SHA256: 256-bit key for message authentication
  • HMAC-SHA512: 512-bit key for stronger HMAC
  • ChaCha20: 256-bit key, stream cipher alternative to AES
History

How It Works

This tool generates cryptographically secure random keys using the Web Crypto API (crypto.getRandomValues()). The generated bytes are true cryptographic randomness from your operating system's CSPRNG (Cryptographically Secure Pseudo-Random Number Generator). Everything runs entirely in your browser - no key material is ever sent to a server.

Symmetric Encryption Keys

Symmetric encryption uses the same key for both encryption and decryption. The key must be kept secret and shared only with authorized parties through a secure channel. Common symmetric algorithms include AES (Advanced Encryption Standard) and ChaCha20.

Key Sizes

The key size determines the strength of the encryption. AES supports 128, 192, and 256-bit keys. A 128-bit key provides 2128 possible combinations - already far beyond brute-force feasibility. A 256-bit key provides an astronomically larger keyspace, suitable for protecting classified information and long-term security.

Output Formats

  • Hexadecimal: Standard representation, 2 hex characters per byte. Commonly used in configuration files and APIs.
  • Base64: Compact encoding, ~33% shorter than hex. Common in JWTs, configuration, and web APIs.
  • Base64URL: URL-safe variant of Base64 (replaces + with - and / with _). Used in JWTs and URL parameters.
  • Decimal Array: Array of byte values (0-255). Useful for programming languages and byte-level work.

Security Notes

  • Never reuse keys: Each encryption operation should ideally use a unique key or key/IV combination.
  • Secure storage: Store keys in a secrets manager, HSM, or encrypted vault - never in source code.
  • Key rotation: Periodically rotate encryption keys to limit exposure from potential compromises.
  • Transport security: Only transmit keys over encrypted channels (TLS, SSH, etc.).

Embed This Util

You can embed this util on your own site as a widget. Adding ?embed=1 to the URL loads a compact version with just the tool itself; no header, menu, or documentation. Paste this snippet into your HTML:


    

Copy snippet Adjust the height to taste.



Feedback

Help us improve this page by providing feedback, and include your name/email if you want us to reach back. Thank you in advance.


Share with