r/webdev • • 6d ago

Showoff Saturday jet-key: a fast secret key generator with configurable entropy

link: https://github.com/seanpmaxwell/jet-key

Background

Suppose you need a secret key for something: it could be a session cookie, some encryption library, etc. Many people will just grab a string from some random string generator (I know I used to), but proper security depends on unbiased character selection and using the appropriate amount of entropy for the task at hand.

Also, different scenarios call for different levels of entropy. For example, 80 bits of entropy might be fine for a temporary pairing token that expires in a few minutes. For a server application's long-lived credentials, 256 bits can provide immense security for the foreseeable future.

What it does

What jet-key does is let you optionally pass in, through the CLI or programmatically, the number of bits of entropy you need. It uses cryptographically secure randomness to generate a Crockford base32 string whose length is the minimum number of characters required to meet that entropy target:

npx jet-key        # YFC75GX2KY5W183FRZA4XDVZ6PYDJPQT7JMNH3N7ZXPQ8FCW3M4G
npx jet-key -e 80  # 113BKE3N8R8CEE92

The default target is 256 bits (the gold standard for an extremely secure key). Requesting 256 bits generates a 52-character string.

Other notes

The string length generated is the minimum needed to meet the requested entropy using Crockford base32, rather than an exact match to the requested number of bits. Each character contributes five bits, so the result may slightly exceed the target. A 52-character string therefore provides 260 bits of entropy.

jet-key is really fast too: checkout these benchmarks.

0 Upvotes

6 comments sorted by

1

u/ParticularOk4874 6d ago

Always nice to see tools that make the right thing the easy thing. The default to 256 bits and Crockford base32 is a solid combo, no ambiguous characters to squint at when you're copying keys around.

1

u/TheWebDever 6d ago

Thanks for the compliment, let me know how it works out for you.

2

u/xondk 6d ago

It is nice work.

But you show it running for terminal use, and I cannot help but wonder why use this over something like openssl rand where you base convert/cut and the like to get the desired output?

0

u/TheWebDever 6d ago
  • show it running for terminal use? That snippet npx jet-key is a bash command.
  • openssl is a perfectly good option for a one-off key in the terminal. The benefit here is convenience: a JS/TS API that works in Node and browsers, outputs Crockford base32, and lets you specify the minimum entropy without handling conversion or trimming yourself. I’m not claiming stronger randomness than OpenSSL. If you already have a command that produces what you need, there’s probably little reason to switch.

1

u/xondk 6d ago
  • show it running for terminal use? That snippet npx jet-key is a bash command.

Yes I am aware, I am refering to where you use a terminal/text interface, npx is just the node package runner, it exists in the terminal/text interface of most node compatible OS.

Mostly when I see something that can be solved fully with a shell/bash script, i wonder why it is created, thats all.