Secret Keys Explained: Hex vs Alphanumeric, and How Long Is Long Enough
Understand how secret key length and format translate into real strength, with the entropy math for hex and alphanumeric keys, plus practical advice on storing, rotating and never sharing keys.
Developers generate secret keys for JWT signing, API tokens, session cookies and encryption, and the question that always comes up is how long the key needs to be. The answer depends on the format, because a character in a hex key carries less randomness than a character in a mixed letters and numbers key. This guide explains the simple math, shows how the BetterUtils Secret Key Generator options compare, and covers the habits that matter more than the length: storage, rotation and keeping keys out of places they should not be.
Entropy in Plain Language
Entropy measures how many equally likely possibilities a key could be, usually expressed in bits. Each extra bit doubles the number of guesses an attacker would need. A key's strength depends on how many characters it has and how many different characters each position can hold. Fewer symbols per position means you need more characters to reach the same strength.
The Two Formats in the Generator
The generator lets you choose between a hexadecimal key, which uses the digits 0 to 9 and the letters a to f, and an alphanumeric key, which uses uppercase letters, lowercase letters and digits. Length can be set from 16 to 128 characters. The key is created in your browser using the secure random number source built into the browser, not a basic pseudo random function.
The Math: Bits Per Character
Each hex character has 16 possible values, which equals exactly 4 bits. Each alphanumeric character has 62 possible values, which is a little under 6 bits, around 5.95. Multiply by length to get total strength.
| Length | Hex strength | Alphanumeric strength |
|---|---|---|
| 16 characters | 64 bits | about 95 bits |
| 32 characters | 128 bits | about 190 bits |
| 43 characters | 172 bits | about 256 bits |
| 64 characters | 256 bits | about 381 bits |
| 128 characters | 512 bits | about 762 bits |
Reaching a 256 Bit Key
Many libraries and standards recommend 256 bits of randomness for signing and encryption keys. With the hex format, that means 64 characters. With the alphanumeric format, it takes about 43 characters, since each character carries more information. Be careful with a rule of thumb that says 32 alphanumeric characters are the same as 64 hex characters. By the numbers, 32 alphanumeric characters give roughly 190 bits, which is still very strong for most uses but is not the same as 256. When a library asks specifically for a 256 bit key, choose the length by the math above.
Which Format Should You Pick?
Choose hex when a library expects a hexadecimal string or raw bytes encoded in hex, because it maps cleanly to binary data. Choose alphanumeric when you simply need a strong string and want more strength per character, or when characters like symbols would cause problems in a config file or a URL. Neither format is weaker when the length is chosen properly, so let the destination decide.
Habits That Matter More Than Length
A long key stored carelessly is worse than a shorter key that is protected. Follow these basics.
- Keep keys in environment variables or a secrets manager, never in source code or in a public repository.
- Use a different key for each environment and each service.
- Rotate keys on a schedule, and immediately if you suspect exposure.
- Never paste a production key into chat, tickets or documents.
- Generate a new key instead of modifying an old one by hand.
Keys Versus Passwords and IDs
A secret key is meant for machines, not for people to remember. If you need a login credential, the Password Generator is a better fit. If you only need a unique identifier that is not secret, a UUID is enough. Using the right tool for each job avoids both weak secrets and unnecessarily complicated identifiers.
Frequently Asked Questions
Is a key created in the browser safe to use?
The generator uses the browser's secure random source. As with any secret, store it carefully and do not share the page contents or screenshots.
Is a longer key always better?
Past 256 bits there is little practical benefit for most uses. Some systems also set a maximum or expect a fixed length, so match what your library requires.
Hex or alphanumeric for a JWT secret?
Either works if the length gives enough strength. Use 64 hex characters or about 43 alphanumeric characters for 256 bits.
Conclusion
Pick the format your system expects, then set the length from the entropy math: 64 hex characters or about 43 alphanumeric characters for 256 bits. After that, the real security comes from how you store, rotate and share the key. Generate your next key with the Secret Key Generator, copy it straight into your secrets manager, and avoid pasting it anywhere else.
Tools mentioned in this guide
Ready to try it yourself?
Use our free tool to get started right away. No signup required!
Try the Tool Now →Related reading
- Password Generator Guide: Create Strong, Secure Passwords
Learn how a password generator creates strong, secure passwords that protect your accounts. Understand what makes a password uncrackable and best practices for password management.
- Why Privacy-Focused Web Utilities Are Essential for Marketers
Privacy-focused web utilities run entirely in your browser, so campaign data, passwords, and previews never touch a third-party server. Here's why that matters.