Skip to content
faker.tools
All 79

Plate VI · Network, Web & System Telemetry Generators

Session ID & Token Generator

Session IDs, cookies, JWT-shaped tokens, API keys and CSRF tokens.

#TokenType
1P2S5SsETrPgn8fvXVmZXCuv9apz1FEJjbucp7Ei4Vik1dcThsession
2hR2VqezSl0FtoNr5cm5tqIs0PwTHMbhndKsNGDNcNqq2zvyZsession
36dY6BA1toCAmkdoweNg128lBLTqHvw3OUbolyxdwunJou65Ssession
4hVJ4P4l3fA6CliOdKuagMc7BBUcxdPyxkjWtVnnEy8XcJHqpsession
51FERJpLq6Z4LnmxOFObpnQUmtYj8BezFLIzlTgdRUMrbwqH0session
6cRxcJzkjTqeqyzd3AHLfeiCkBY5MOumQT1eLxujYHIDow62Xsession
7v37wjgln7LNfKwGZaq2ZoHtWxBsGicONhj74nnrGxdF67j4Osession
8NsFNacYEplrjjnNsXDGtOxh3ZH3YZwDp1plMOc6ntx3B7XZ0session
9dxpDMGLtjO2B1YEjYhPPfP2GPVixiAyAi3PVMEsx1ZyAmTxLsession
10K5L2RTZuz9qR3P1WeQH8ypDCD6InM4WvQ0qwZIxp3MIHtahMsession
10 rows · 805 BGenerated in your browser · Session ID & Token Generator

A Set-Cookie header for a session needs HttpOnly, Secure and a SameSite policy, and the cookie is the only place those live. This produces the whole header, attributes included, rather than just the value.

What you can control

  • Complete Set-Cookie headers with the security attributes a session cookie should carry.
  • JWT-shaped tokens with a real base64url header and payload, so a decoder can read the claims.
  • API keys use the sk_live and sk_test prefix convention that makes an environment mix-up obvious.
  • Token length is adjustable, for testing a column limit or a header size cap.

What this is not

JWT tokens here have a syntactically valid structure but a random signature, so any library will reject them at verification. That makes them useful for testing the failure path and useless for the success path.

Questions

Will these JWTs verify?

No. The signature segment is random rather than an HMAC of the header and payload. Every library will reject them — which is exactly what you want when testing your error handling.

HttpOnly blocks JavaScript access, Secure restricts the cookie to HTTPS, and SameSite=Lax stops it being sent on most cross-site requests. All three matter for a session cookie.

Why prefix API keys with sk_live or sk_test?

So a key pasted into the wrong environment is visible at a glance. Stripe popularised the convention and it has saved a lot of accidental live charges.

Next in Network

All 10