type enum Credential shape: apiKey (prefix + 32 base62 chars), jwt (decodable header.payload.signature), hex (raw lowercase hex secret) or base64 (raw padded base64 secret).
Clearly fake API keys, JWTs and hex/base64 secrets — structurally valid enough to exercise parsers and middleware, cryptographically meaningless by design.
Generated test data for fixtures and development
| Parameter | Type | Default & allowed | Description |
|---|---|---|---|
type | enum | default: apiKey allowed: apiKey | jwt | hex | base64 example: jwt | Credential shape: apiKey (prefix + 32 base62 chars), jwt (decodable header.payload.signature), hex (raw lowercase hex secret) or base64 (raw padded base64 secret). |
prefix | string | allowed: 1 – 16 example: pk_live_ | Key prefix for type=apiKey (1–16 characters, e.g. pk_live_). Defaults to sk_test_. Only applies to apiKey — set on any other type it is ignored with a warning. |
bytes | int | allowed: 8 – 64 example: 16 | Secret strength in random bytes for type=hex (output is bytes × 2 characters) and type=base64 (decodes back to exactly this many bytes). Defaults to 32. Ignored with a warning for other types. |
type enum Credential shape: apiKey (prefix + 32 base62 chars), jwt (decodable header.payload.signature), hex (raw lowercase hex secret) or base64 (raw padded base64 secret).
prefix string Key prefix for type=apiKey (1–16 characters, e.g. pk_live_). Defaults to sk_test_. Only applies to apiKey — set on any other type it is ignored with a warning.
bytes int Secret strength in random bytes for type=hex (output is bytes × 2 characters) and type=base64 (decodes back to exactly this many bytes). Defaults to 32. Ignored with a warning for other types.
| Parameter | Type | Default & allowed | Description |
|---|---|---|---|
count | int | default: 10 allowed: 1 – 100 example: 3 | How many records to generate (1–100). |
seed | int | example: 42 | Deterministic output: the same seed always returns the same records. Omit for random (the used seed is echoed in meta.seed). |
fields | list | example: value,type | Return only these fields (comma-separated). Mutually exclusive with 'exclude'. |
exclude | list | example: claims | Return all fields except these (comma-separated). |
format | enum | default: json allowed: json | ndjson | csv example: csv | Response format: json envelope, ndjson (one record per line) or csv. |
pretty | boolean | default: false example: true | Pretty-print the JSON response. |
unwrap | boolean | default: false example: true | Drop the envelope: return the raw array/object without data/meta wrapper. |
count int How many records to generate (1–100).
seed int Deterministic output: the same seed always returns the same records. Omit for random (the used seed is echoed in meta.seed).
fields list Return only these fields (comma-separated). Mutually exclusive with 'exclude'.
exclude list Return all fields except these (comma-separated).
format enum Response format: json envelope, ndjson (one record per line) or csv.
pretty boolean Pretty-print the JSON response.
unwrap boolean Drop the envelope: return the raw array/object without data/meta wrapper.
| Field | Type | Description | Example |
|---|---|---|---|
value | string | The generated credential in the requested format. | sk_test_h2vTQEnAVoZkW8eFqYbJ3R7xLcM5pDgU |
type | string | Echo of the type parameter for this record: apiKey | jwt | hex | base64. | apiKey |
claims nullable | object | For type=jwt only: the token's decoded payload (sub, name, iat, exp) so tests can assert against it without a decoder. null for all other types. | {"sub":"user_4f9a2c1e8b3d","name":"Emily Carter","iat":1765800000,"exp":1765803600} |
value string The generated credential in the requested format.
example: sk_test_h2vTQEnAVoZkW8eFqYbJ3R7xLcM5pDgU
type string Echo of the type parameter for this record: apiKey | jwt | hex | base64.
example: apiKey
claims object nullable For type=jwt only: the token's decoded payload (sub, name, iat, exp) so tests can assert against it without a decoder. null for all other types.
example: {"sub":"user_4f9a2c1e8b3d","name":"Emily Carter","iat":1765800000,"exp":1765803600}
/api/tokens?count=5&seed=42 {
"data": [
{
"value": "sk_test_TfbJW24PmwhOdMnXJsfoKYnrrJ1wj6NV",
"type": "apiKey",
"claims": null
},
{
"value": "sk_test_20RWzAHWdjtnnhfOwoFKrxZ5oDQOTCvX",
"type": "apiKey",
"claims": null
},
{
"value": "sk_test_r7LSZ0a29n0LfmVCYwumy1hZlG4POxaN",
"type": "apiKey",
"claims": null
},
{
"value": "sk_test_9a2AxqgJ8v4ux9zwiS1eSIPb5Nk12bGN",
"type": "apiKey",
"claims": null
},
{
"value": "sk_test_piRF2hvtqHpXj4qeMYww8r4J4FT7NEem",
"type": "apiKey",
"claims": null
}
],
"meta": {
"endpoint": "tokens",
"count": 5,
"seed": 42,
"params": {
"type": "apiKey",
"prefix": "sk_test_"
},
"generatedAt": "2026-07-30T15:14:08.000Z"
}
} /api/tokens?prefix=pk_live_&count=3&seed=7 {
"data": [
{
"value": "pk_live_gqYBkTuBGBQyP6kmpt6eAETzQ4wrbNKW",
"type": "apiKey",
"claims": null
},
{
"value": "pk_live_ZbKm1uoKneiYeYpqHLQYDtaQdt0hlYYZ",
"type": "apiKey",
"claims": null
},
{
"value": "pk_live_Sldk36kpkuDjMeNu5oiDfoavt4ho84ud",
"type": "apiKey",
"claims": null
}
],
"meta": {
"endpoint": "tokens",
"count": 3,
"seed": 7,
"params": {
"type": "apiKey",
"prefix": "pk_live_"
},
"generatedAt": "2026-07-30T15:14:08.000Z"
}
} /api/tokens?type=jwt&count=2&seed=11 {
"data": [
{
"value": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImZha2UifQ.eyJzdWIiOiJ1c2VyXzVmNjdiY2QyYzc2ZiIsIm5hbWUiOiJHcmVnZyBBbHRlbndlcnRoIiwiaWF0IjoxNzg1MTM2ODU2LCJleHAiOjE3ODUxNDA0NTZ9.PyXNKxhPqYPTLT7a50bVjW-MqVtkGM-89RvB5KhRh2U",
"type": "jwt",
"claims": {
"sub": "user_5f67bcd2c76f",
"name": "Gregg Altenwerth",
"iat": 1785136856,
"exp": 1785140456
}
},
{
"value": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImZha2UifQ.eyJzdWIiOiJ1c2VyX2Y1ZmQzYmI0MGMxMyIsIm5hbWUiOiJFdWdlbmUgUHJpY2UiLCJpYXQiOjE3ODM5NDYxOTgsImV4cCI6MTc4Mzk0OTc5OH0.5YAsDVcBBg-aNMwtsjfMNTMDryPxvjhduo-Qw3N7yH4",
"type": "jwt",
"claims": {
"sub": "user_f5fd3bb40c13",
"name": "Eugene Price",
"iat": 1783946198,
"exp": 1783949798
}
}
],
"meta": {
"endpoint": "tokens",
"count": 2,
"seed": 11,
"params": {
"type": "jwt"
},
"generatedAt": "2026-07-30T15:14:08.000Z"
}
} /api/tokens?type=hex&bytes=16&count=5 {
"data": [
{
"value": "7aad995187091268c7f1b364a45dcc8b",
"type": "hex",
"claims": null
},
{
"value": "0a017286fd2c4986a4bbe6cdcab4aa63",
"type": "hex",
"claims": null
},
{
"value": "db1e59779001970825cd0258a9c98133",
"type": "hex",
"claims": null
},
{
"value": "2795092df4d8af5123ed11ebf426fef2",
"type": "hex",
"claims": null
},
{
"value": "d5b76f400cb3ece5da48d388bb10d8a9",
"type": "hex",
"claims": null
}
],
"meta": {
"endpoint": "tokens",
"count": 5,
"seed": 42,
"params": {
"type": "hex",
"bytes": 16
},
"generatedAt": "2026-07-30T15:14:08.000Z"
}
} /api/tokens?type=base64&bytes=48&count=3 {
"data": [
{
"value": "eq2ZUYcJEmjH8bNkpF3Mi1Hiq89Tjs3c208F8bsbX4FhNsYa2RTP8/yBfi6BR0qF",
"type": "base64",
"claims": null
},
{
"value": "CgFyhv0sSYaku+bNyrSqY/HRQVbe95MVzzhuZHk07or+z6jgkADa4GVTXFiAV1zT",
"type": "base64",
"claims": null
},
{
"value": "2x5Zd5ABlwglzQJYqcmBM43y6sj5BbSTxUMQaWX0lmB+BVtcVawM5OItz/lePL2Y",
"type": "base64",
"claims": null
}
],
"meta": {
"endpoint": "tokens",
"count": 3,
"seed": 42,
"params": {
"type": "base64",
"bytes": 48
},
"generatedAt": "2026-07-30T15:14:08.000Z"
}
} Generates clearly fake credentials: every value is structurally valid — the right shape, alphabet and length to exercise parsers, validators, masking and secret-scanning logic — but cryptographically meaningless. Nothing is signed with or derived from a real secret, and nothing can authenticate anywhere. The defaults advertise it too: API keys start with sk_test_ and JWT headers carry "kid": "fake".
Four shapes via type:
prefix + 32 base62 characters, Stripe-style. Change the look with prefix (1–16 chars, e.g. pk_live_; default sk_test_).header.payload.signature structure in unpadded base64url. The header is {"alg":"HS256","typ":"JWT","kid":"fake"}; the payload carries sub, name, a past iat (between 1 hour and 30 days before the request) and exp = iat + 3600. It decodes in any JWT library (or jwt.io), and the decoded payload is returned alongside as the claims field so your assertions don't need a decoder. The signature is just 32 random bytes — verification fails by design.bytes random bytes as lowercase hex (bytes × 2 characters; the default 32 bytes gives a fake-SHA-256-sized 64-char string).bytes random bytes as standard, padded base64.prefix only applies to apiKey, and bytes only to hex and base64 — setting one on the wrong type adds a notice to meta.warnings instead of silently no-opping. With a seed, the same request returns byte-identical credentials forever.
They decode like real ones — header, payload with readable claims, signature — but they're fake and won't verify against any real issuer. That's the point.
Yes — type=apiKey with the default sk_test_ prefix or your own prefix, plus bytes for length, matches most providers' shapes.
Yes — they look real to parsers but unlock nothing. If your secret scanner flags them, allow-list the fake prefix you chose.
Generate seed-reproducible UUIDs and compact IDs, or inspect any canonical UUID's RFC 9562 variant, version and UUIDv7 timestamp fields.
Random password generator with length, uppercase/digit/symbol toggles, look-alike exclusion, and an honest entropy estimate with a strength rating.
Fake git commits — Conventional Commits or plain messages, 40-char hashes, safe author emails, dates in your range and realistic diff stats. Fully seedable.
Random internet building blocks — valid IPv4/IPv6 addresses, locally-administered MACs, non-resolvable .test domains and URLs, slugs, ports and TLDs.
Decode any compact JWS/JWT — header, payload, registered claims and exp/nbf/iat evaluated at a real or supplied clock. Signatures are never verified.
Mock LLM completion fixtures with coherent token usage, tool calls and a replayable delta stream whose chunks concatenate to the exact message.