Skip to content
apikey.tools

64 tools · zero uploads

Key material,
made in your browser.

Generate, inspect, sign and audit API keys, JWTs and webhook secrets. Every byte comes from your own machine's CSPRNG and stays there — there is no server to send it to.

Vendor signatures
95
Providers
67
Input bytes sent
0
GENcrypto.getRandomValues32 B · 256 bits
Generated keyDrawing entropy…
Full generator →1.8×10^57 years to brute force
Strength256 bits
Encoding

Most used

The six people reach for first.

The full bench

Seven channels, 64 instruments.

Why in-browser matters here

A pasted key is a shared key

The moment a credential is posted to someone else's server it must be treated as compromised — logged, cached, or retained in a backup you cannot see. These tools give that server no chance to exist.

Randomness with provenance

Keys are drawn from crypto.getRandomValues, your operating system's CSPRNG. No server can prove what its generator did; your own machine needs no such proof.

Verify it yourself

Open any tool, turn off your network, and keep working. Watch the network tab while you type and you will see nothing leave. That is a stronger assurance than a privacy policy.