Verso Pad
Private by default · No uploads

API Key Generator — Free Online Tool

Web Crypto powered

Generate secure keys

Create strong API keys and tokens locally. Generated values are never stored, logged, or sent anywhere.

Generated keys

Your keys will appear here

Choose a preset and generate up to 50 at once.

Nothing is saved. Closing or refreshing this page permanently clears generated keys.
About this free online tool

Free secure API key, UUID, and token generator

Generate random API keys, prefixed secrets, UUIDs, hexadecimal tokens, and Base64 values locally using the browser Web Crypto API.

What is this tool?

Verso Pad API Key Generator creates high-entropy identifiers and secret-like values without sending generated output to an application server. It uses the browser Web Crypto API for cryptographically secure random bytes rather than Math.random. Choose a ready-made key type, set an appropriate length and count, add a recognizable prefix, and copy or download the generated values for use in development, testing, or a secure provisioning workflow.

Random API Key mode lets you combine uppercase letters, lowercase letters, numbers, and symbols. Secret and public presets provide conventional sk_ and pk_ prefixes that make credentials easier to identify in logs and configuration, although a prefix does not change the security of the random portion. Hex Token produces hexadecimal characters, Base64 Secret creates URL-safe Base64 text, and UUID v4 generates standard random identifiers intended primarily for uniqueness rather than authentication.

Generated values exist only in memory. They are deliberately excluded from local storage, so refreshing or closing the page clears them. Preferences such as key type, length, prefix, count, and character groups may be remembered locally for convenience, but previous keys are not restored. This separation reduces accidental persistence while still making repeated generation sessions practical.

A generated token is only one part of a secure credential system. Select a length appropriate to the threat model, transmit secrets over protected channels, store them in a secret manager, avoid placing them in source control, and support rotation and revocation. Public identifiers, UUIDs, and authentication secrets serve different purposes; do not use a UUID as a password merely because it looks random.

Features

Web Crypto randomness

Generate random material using crypto.getRandomValues, with rejection sampling for custom alphabets to avoid biased character selection.

Useful presets

Choose random API keys, secret keys, public keys, UUID v4 identifiers, hexadecimal tokens, or URL-safe Base64 secrets for common development workflows.

Custom length and count

Create one or many values at once and adjust the random portion to suit testing, integration, or production provisioning requirements.

Prefixes and character groups

Add an environment or credential-type prefix and control whether custom random keys include uppercase, lowercase, numeric, and symbol characters.

No secret persistence

Generated output is not written to browser storage. A refresh clears the list, while non-secret generator settings can remain available on the same device.

Copy or download

Copy an individual value or download the current batch as text so it can be transferred immediately into an appropriate secret-management workflow.

Example usage: Create prefixed keys for a service integration

  1. Choose Secret Key and set the random length required by the receiving service.
  2. Keep a recognizable sk_ prefix or replace it with a project-specific prefix that does not expose sensitive information.
  3. Generate the required number of values and copy each one directly into the destination secret manager.
  4. Record only safe metadata such as ownership and rotation date, then refresh the page to clear the generated list.

The random values are created locally and are not recoverable from Verso Pad. Confirm the destination accepted each key before clearing the page because there is no server-side history or recovery feature.

Frequently asked questions

Are generated API keys stored by Verso Pad?

No. Generated keys remain in page memory and disappear on refresh or close. The browser may remember generator settings, but not the generated secret values.

Is UUID v4 suitable as an authentication secret?

UUID v4 is designed mainly to provide unique identifiers. For authentication, use a sufficiently long random API key or token and follow the requirements of the system that will verify it.

How long should an API key be?

The correct length depends on the alphabet, threat model, and service requirements. Longer random values generally provide more entropy, but always follow the receiving platform’s documented format and storage guidance.

Can a generated key be recovered later?

No. Verso Pad intentionally keeps no key history. Copy the value to its secure destination before leaving the page, and generate a replacement if the original is lost.