Hash Generator (MD5, SHA-256)→Specialized Version
#️⃣

Token Generator

Token Generator

Bearer token

Bytes of entropy, hex encoded — safe in a header or URL.

  • c79055d98f6a5ecc25d5a65d810ecc6abd414ba967412af90e284d4fa57856d9
  • ae4b6cc0691c5e30af786a56366f678f0ffa862fc134a162050f7e10f5978390
  • f31ae0f9e0557dedf5321558d630e05798dbae0609579f43940154861a8c8dd4

Values come from crypto.getRandomValues, the browser's CSPRNG. They are generated locally and never sent anywhere — but a secret that has been displayed on screen is only as private as the screen.

Token Generator

A bearer token is a credential where possession alone grants access — no signature to verify, no identity to prove. That simplicity is the point and the risk: whoever holds it is authorised.

Sizing

For a token that must resist guessing, 128 bits of entropy is the working floor and 256 bits is comfortable. Hex encoding gives 4 bits per character, base64url gives 6:

BytesHex lengthBase64url lengthEntropy
163222128 bits
244832192 bits
326443256 bits
489664384 bits
Hex is longer but survives every system that has ever mishandled + or /.

Opaque Tokens Versus JWTs

Opaque random tokenJWT
Contains dataNo — it is a lookup keyYes, readable by anyone
VerificationDatabase or cache lookupSignature check, offline
RevocationImmediate: delete the rowHard; needs a denylist
Size~32–64 charactersSeveral hundred bytes
Leaks informationNothingEvery claim inside it
A random token is the better default for sessions and API access precisely because revocation is trivial. JWTs earn their complexity when verification must happen without a shared datastore.

Short Expiry Plus Refresh

The standard arrangement pairs a short-lived access token with a longer-lived refresh token. A stolen access token is useful for minutes; the refresh token is stored more carefully, used rarely, and can be revoked centrally.

Rotating the refresh token on each use adds theft detection: if an old refresh token is presented, someone has a copy, and the whole family can be invalidated.

Handling

  • Always over TLS. A bearer token in plaintext is a handed-over credential.
  • Never in a URL — logs, history and Referer headers all retain them.
  • Hash before storing, exactly as with an API key.
  • Compare in constant time, so response timing does not leak a prefix match.
  • Bind to a context where you can — client, audience, scope — so a leaked token is less
useful elsewhere.

The Avalanche Effect

A one-character change produces a completely different digest — not a similar one. That property is what makes a hash useful as a fingerprint:

InputMD5CRC32
hello5d41402abc4b2a76b9719d911017c5923610a686
hello.d94c10e437d18531e122ed0b45badd2a0a39d4f1
Hello8b1a9953c4611296a827abf8c47804d7f7d18982
hello and Hello differ by one bit of one byte, and share no part of their output. RIPEMD-160 of hello is 108f07b8382412612c048d07d13f814118445acd, and of Hello is d44426aca8ae0a69cdbc4021c64fa5ad68ca32fe — same story.

Digest Length and Collision Resistance

AlgorithmOutputBirthday boundStatus
CRC3232 bits~77,000 valuesChecksum only
MD5128 bits2⁶⁴ in theoryBroken — collisions in seconds
SHA-1160 bits2⁸⁰ in theoryBroken — SHAttered, 2017
RIPEMD-160160 bits2⁸⁰No practical attack
SHA-256256 bits2¹²⁸Current standard
SHA-512512 bits2²⁵⁶Standard, faster on 64-bit
The birthday bound is where a 50% chance of *some* collision appears among random inputs. MD5 and SHA-1 fall far short of theirs because both have practical collision attacks — you can construct two different files with the same digest, which is precisely what a signature must prevent.

Never Hash a Password With These

A general-purpose hash is designed to be fast, which is exactly wrong for passwords: speed helps the attacker. Use a deliberately slow KDF — bcrypt, scrypt or Argon2id — with a per-password salt. A GPU tries billions of SHA-256 guesses a second and a few thousand bcrypt guesses a second, and that gap is the entire defence.

Frequently Asked Questions

Is this TOKEN truly random?

Yes, generation uses cryptographically secure random number generation (CSPRNG) suitable for security-sensitive applications.

Can two generated values ever be the same?

While theoretically possible, the probability is astronomically low. For UUIDs, there are 2^122 possible values—collision is practically impossible.

Are generated values stored anywhere?

No, all generation happens locally in your browser. Nothing is sent to any server, ensuring complete privacy.

Related Tools

Explore other tools you might find useful:

More Hash Generator (MD5, SHA-256) tools

You might also need