About Cryptographic Secret Key Generator (.env)
Generate high-entropy 128-bit, 256-bit, and 512-bit symmetric secret keys for JWT signing (HS256/HS512), AES encryption, session cookies, and application .env files.
Key Capabilities & Features
- 128-bit, 256-bit, and 512-bit cryptographic key sizes
- Output formats in Hex, Base64, and Base64URL
- One-click `.env` snippet generation (e.g. JWT_SECRET, APP_KEY)
- Hardware-backed CSPRNG entropy
- 1-Click copy
How to Use Cryptographic Secret Key Generator (.env)
Select Bit Length
Choose 128-bit (standard), 256-bit (recommended for AES/JWT), or 512-bit.
Select Output Encoding
Choose Hexadecimal, Base64, or Base64URL.
Copy Key
Copy the secret key into your production `.env` environment file.
Privacy & In-Browser Execution Guarantee
Secret keys are generated strictly in local RAM via window.crypto.getRandomValues. Never stored or logged anywhere.
Frequently Asked Questions
How many bits are recommended for JWT secrets?
For HMAC-SHA256 (HS256), a secret key of at least 256 bits (32 bytes) is required by RFC 7518 to prevent brute-force recovery.
Where should I store generated .env secrets?
Store them in a .env file that is explicitly excluded in .gitignore, or inject them into production using managed cloud secret vaults.
Should I use Base64 or Hex for environment variable secrets?
Both are fully supported. Base64 produces a more compact string, while Hex (0-9, a-f) avoids special characters and copy-paste padding confusion.