What is a random token?
A random token is an opaque value that an application can map to a server-side record or authorization decision. The value should be unpredictable, but randomness alone does not add an expiration, user identity, permission, signature, or revocation policy.
Session tokens
A session token identifies an authenticated browser session. Store it in a secure transport mechanism appropriate to the application, rotate it after meaningful authentication changes, expire it server-side, and invalidate it when the session ends. Do not put session tokens in analytics, logs, or public URLs.
CSRF tokens
A CSRF token helps a server distinguish intended state-changing requests from forged ones. It is not a password or authentication credential. Bind and validate it using the application’s framework or established CSRF defense pattern instead of treating a random string as a complete defense by itself.
Password reset and invitation tokens
Reset and invitation links should use single-use, time-limited tokens. Store a verifier rather than the raw value when practical, invalidate earlier tokens after a successful action, and avoid exposing the token through referrer data, third-party scripts, screenshots, or support messages.
Bearer tokens
A bearer token authorizes whoever possesses it. Use HTTPS, limit its scope and lifetime, keep it out of browser history and logs, and provide a revocation path. The optional header format simply prepends Authorization: Bearer; it does not turn the opaque value into an OAuth access token.
Base64URL or hexadecimal?
Base64URL is compact and avoids characters that require URL encoding. Hexadecimal is longer but uses only digits and letters A through F. Both represent the same random bytes and therefore provide the same entropy at the selected bit size.
Random tokens versus API keys and JWTs
Use this tool for temporary or application-mapped opaque tokens. Use the API key generator for long-lived credentials with labels and batch environment output. A JWT is a structured signed object; the JWT secret generator creates only symmetric signing secret material, not a finished token.
Technical basis
Values are created with the browser’s cryptographically secure Web Crypto random-number source. Application handling should follow a reviewed framework workflow and established guidance such as the OWASP Forgot Password Cheat Sheet.