14
I'm using security tokens to create not guessable URLs like this (16 bytes, hex)
http://example.com/something/private/b5f8c21a628e12b39786fb8ef9561d31
The token is something like a shared passwords: Who knows the URL is allowed to access the resource.
How many bytes should a secure random value have to be appropriate for secure URLs?