Shared-Key Generator

Generate random 128-bit or 256-bit keys for HMAC, AES-GCM, AES-CBC, AES-CTR and AES-KW, and export them as JWK, Base64 or a raw binary file. Keys come from the browser's Web Crypto API and stay on your device. Handy as an HMAC secret for HS256 JWTs or an AES key for testing.

About this tool

What does the Shared-Key Generator do?

A shared key (symmetric key) is a single secret used by both sides: the same key encrypts and decrypts with AES, or creates and checks a MAC with HMAC. Its security depends entirely on being random and kept secret. This tool generates such keys with the browser's cryptographically secure Web Crypto API and outputs them in a format your code can import.

How to use

  1. Choose an Algorithm (HMAC, AES-CTR, AES-CBC, AES-GCM or AES-KW). A key is generated immediately.
  2. Choose the Key length (bits): 128 or 256. For HMAC, also choose the Hash (SHA-256, SHA-384 or SHA-512).
  3. Choose the Format: JWK, Base64 or Raw. Changing the format converts the current key instead of creating a new one.
  4. Copy or download the key from Shared key using the buttons in the editor.
  5. Click Regenerate for a new key with the same settings.

Output formats

FormatOutputTypical use
JWKJSON Web Key with kty: "oct", k, alg (for example HS256 or A256GCM) and key_opscrypto.subtle.importKey('jwk', …), JOSE libraries
Base64The key bytes as standard Base64Environment variables, config files, HS256 secrets
RawThe key bytes as a binary file (key)Tools that read a key file

Features

  • HMAC and four AES modes supported by Web Crypto
  • 128-bit or 256-bit keys
  • JWK, Base64 and raw binary output, with conversion between them for the same key
  • Copy and download buttons; raw keys are shown as size and SHA-1 fingerprint because they are binary

Which algorithm should I pick?

  • AES-GCM: authenticated encryption; the usual choice for encrypting data
  • AES-CBC / AES-CTR: older modes without built-in integrity; combine with HMAC if you use them
  • AES-KW: wrapping (encrypting) other keys
  • HMAC: message authentication and JWT HS256/384/512 signatures

The algorithm and hash choice mainly affect the JWK metadata (alg, key_ops). The key itself is simply random bytes of the selected length.

FAQ

Is the key generated securely and kept private?

Yes. Keys are generated with crypto.subtle.generateKey in your browser and are not sent anywhere. The current key is saved in this browser's storage so it is shown again next time; click Regenerate if you want to leave a different key behind on a shared device.

How do I use the key as a JWT secret?

Select HMAC, choose the Base64 format and copy the key. In the JWT tool, paste it into Secret and check Secret is base64 encoded.

Why is AES-192 not available?

Only 128 and 256 bits are offered. Some browsers do not support 192-bit AES keys, and 256 bits is the common choice for strong keys.

Can I enter my own password to derive a key?

No. This tool generates random keys only. To turn a password into a key, use a key derivation function such as PBKDF2 or Argon2 in your code.