Generate a secure random API token.
Base64url-encoded, safe to use directly in URLs, headers or as an API key.
It uses the Web Crypto API's getRandomValues to generate cryptographically secure random bytes, then encodes them as base64url — safe to use directly in URLs, HTTP headers or JSON without escaping.
256-bit (32 bytes) is a strong, common default for API keys and session tokens. Use a larger size for long-lived secrets or where extra margin against future brute-force attacks matters.
No — it's generated and displayed entirely in your browser, and never leaves your device.