Salt & Random Token Generator
CryptoGenerate cryptographically secure random salts and tokens as hex or Base64, using crypto.getRandomValues.
On this page
What is a salt?#
A salt is a piece of random data you mix into a hashing process so that two identical inputs produce different outputs. Its job is uniqueness, not secrecy: a salt can sit in plain text next to the hash it protects, and it still defeats an attack that depends on every user with the same password hashing to the same digest. Once each password has its own salt, an attacker cannot reuse one precomputed table across the whole database — they have to recompute per entry.
This page generates cryptographically strong random bytes with crypto.getRandomValues and hands them to you in three encodings: hex (two characters per byte, the convention for password salts and integrity tokens), base64 (more compact), and base64url (the URL- and filename-safe variant that swaps +// for -/_ and drops the = padding, used in JWTs and signed URLs).
The same primitive doubles as a general-purpose random-token generator: API keys, nonce values, opaque IDs, and one-time tokens are all “some random bytes, encoded as text”, which is exactly what this produces.
How to use it#
- Set the number of bytes. The default of 16 (128 bits) is the standard salt size; the field accepts up to 8192 for when you need a longer token.
- Pick a format: hex, base64, or base64url.
- Click Generate, then Copy. The status line shows how many bits of entropy the result represents (bytes × 8), so you can confirm at a glance that you got what you asked for.
Key features#
- Unbiased random bytes. Sourced from
crypto.getRandomValues, the browser’s cryptographically strong generator. - Three encodings. hex for salts and checksums; base64 for compact tokens; base64url for anything that travels in a URL, filename, or JSON.
- Honest entropy reporting. The status line states the actual bit count rather than the encoded string length, which is easy to misread.
- Up to 8192 bytes. The same tool serves a 16-byte salt and a 256-byte key blob.
- Zero upload. Generation is local; the random bytes are never transmitted.
Worked example#
Generate 16 bytes in each of the three formats. A 16-byte draw is 128 bits of entropy, and the encoded lengths are fixed regardless of the random values:
- hex — 32 characters, e.g.
7a4c9f1e0b8d2635c4a1e9f07b2d4861 - base64 — 24 characters with
==padding, e.g.8MDwarqMD7B594C5hCB1zQ== - base64url — 22 characters, padding stripped, e.g.
8MDwarqMD7B594C5hCB1zQ
(The values above illustrate the shape; your actual output differs every click because the bytes are freshly random.) Bump to 32 bytes for a 256-bit salt or key and the lengths grow deterministically: 64 hex characters, 44 base64 characters, 43 base64url characters. That fixed relationship between byte count and encoded length is a quick way to sanity-check that you generated the size you intended.
FAQ#
Does a salt need to be secret?#
No. A salt’s purpose is uniqueness — it ensures that hashing the same password twice yields different digests. It is stored alongside the hash in plain text, and that does not weaken the scheme. The thing that must stay secret is the key in HMAC or the password in encryption, not the salt.
How many bytes should I generate?#
16 bytes (128 bits) is the standard for password salts and most tokens — it makes accidental collisions effectively impossible. For session tokens or anything you want to last a long time against a well-funded attacker, 32 bytes (256 bits) is a comfortable margin. Anything beyond that is usually overkill unless a specific protocol requires it.
What is the difference between base64 and base64url?#
Both encode the same bytes, but base64 uses + and /, which break URLs and filenames, and pads with =. base64url replaces those with - and _ and drops the padding, so the result can be dropped straight into a URL path, a query string, or a filename without escaping. Use base64url for JWTs, signed URLs, and opaque tokens; use plain base64 when the output stays inside data fields.
Can I use this as an API key?#
Yes. Generate 32 bytes in base64url and you have a 43-character token with 256 bits of entropy — more than enough for an API key or a long-lived bearer token. Just make sure to copy it immediately, since the value is generated locally and cannot be recovered later.