Which AES key size should you choose?
AES accepts only 128-, 192-, or 256-bit keys. AES-256 is a common conservative default for a new system, but the correct choice is the size supported by your cryptographic library, protocol, and interoperability requirements.
Why the output lengths differ
A 256-bit key is always 32 raw bytes. Hex represents each byte with two characters, so AES-256 becomes 64 hex characters. Base64 uses fewer characters, and unpadded Base64URL is 43 characters. The encoding changes only the representation—not the underlying random key or its entropy.
Decode before importing the key
Cryptographic APIs usually need raw bytes or a native key object. If you copy a Base64URL, Base64, or hexadecimal value into configuration, decode it exactly once before importing it. Passing the visible text characters directly produces different bytes and may create an invalid key length.
Use authenticated encryption
AES is a block cipher, not a complete message format. Prefer an authenticated encryption mode such as AES-GCM when your platform supports it. Generate a fresh nonce according to the mode’s requirements for every encryption operation and never reuse a GCM nonce with the same key. Store or transmit the nonce with the ciphertext; it does not need to be secret.
Keep keys separate from passwords
Do not paste a human password into an AES key field or pad it to the required length. Password-based encryption needs a dedicated key-derivation function with a random salt and appropriate cost settings. This generator produces uniformly random key material instead.
Storage, access, and rotation
Store production encryption keys in a managed key service, hardware security module, or appropriately protected secrets system. Restrict access, avoid logging key material, maintain backups only where the design requires them, and plan rotation before deployment. Losing an encryption key can make the protected data permanently unrecoverable.
Sources and technical basis
AES key sizes follow the NIST FIPS 197 Advanced Encryption Standard. Random bytes come from the browser’s Web Crypto getRandomValues() API. For browser implementations, review the SubtleCrypto importKey() documentation and the consuming system’s own requirements.
Related developer tools
Laravel APP_KEY generator creates the framework's required base64: format. API key generator creates opaque application credentials with optional prefixes and batch output. JWT secret generator creates HMAC signing secrets. Use this AES page only when a symmetric encryption system requires raw AES key bytes.