Generate random 128-bit or 256-bit keys for HMAC, AES-GCM, AES-CBC, AES-CTR and AES-KW, and export them as JWK, Base64 or a raw binary file. Keys come from the browser's Web Crypto API and stay on your device. Handy as an HMAC secret for HS256 JWTs or an AES key for testing.
A shared key (symmetric key) is a single secret used by both sides: the same key encrypts and decrypts with AES, or creates and checks a MAC with HMAC. Its security depends entirely on being random and kept secret. This tool generates such keys with the browser's cryptographically secure Web Crypto API and outputs them in a format your code can import.
| Format | Output | Typical use |
|---|---|---|
| JWK | JSON Web Key with kty: "oct", k, alg (for example HS256 or A256GCM) and key_ops | crypto.subtle.importKey('jwk', …), JOSE libraries |
| Base64 | The key bytes as standard Base64 | Environment variables, config files, HS256 secrets |
| Raw | The key bytes as a binary file (key) | Tools that read a key file |
The algorithm and hash choice mainly affect the JWK metadata (alg, key_ops). The key itself is simply random bytes of the selected length.
Yes. Keys are generated with crypto.subtle.generateKey in your browser and are not sent anywhere. The current key is saved in this browser's storage so it is shown again next time; click Regenerate if you want to leave a different key behind on a shared device.
Select HMAC, choose the Base64 format and copy the key. In the JWT tool, paste it into Secret and check Secret is base64 encoded.
Only 128 and 256 bits are offered. Some browsers do not support 192-bit AES keys, and 256 bits is the common choice for strong keys.
No. This tool generates random keys only. To turn a password into a key, use a key derivation function such as PBKDF2 or Argon2 in your code.