Password Generator
Generate strong random passwords with your own length and character rules.
Generate random strings of any length and character set.
Random String Generator produces strings of whatever length and alphabet you need, using your browser's cryptographic random number generator rather than Math.random.
That distinction matters more than it sounds. Math.random is a predictable pseudo-random generator: given enough output an attacker can work out its internal state and predict everything it will produce next. For a shuffled list that is harmless; for an API key, a password reset token or a session identifier it is a vulnerability. This page uses crypto.getRandomValues, which is seeded by the operating system and designed for exactly this job.
Selection from the alphabet uses rejection sampling rather than a modulo. A naive modulo makes the first few characters of the alphabet very slightly more likely than the rest, and that bias is measurable and avoidable, so it is avoided.
Character sets are configurable because requirements differ. Hexadecimal for tokens that go in URLs, alphanumeric for things people may have to read aloud, the full printable set for maximum entropy per character, or an unambiguous set with no confusable characters for codes that get typed by hand.
Everything runs inside your browser. Nothing you paste is uploaded, logged or stored, which matters when the input is a client list, an internal URL map or anything else you would not post publicly.
The random string generator is used by writers, developers, students, marketers and anyone else who needs the job done once without installing software. Common cases include:
Yes. It uses crypto.getRandomValues, the browser's cryptographically secure generator seeded by the operating system, not Math.random. The strings are suitable for tokens and keys.
For a secret such as an API key, aim for at least 128 bits of entropy: 32 hex characters or 22 alphanumeric ones. The page shows the entropy for your current settings.
Codes that humans type or read aloud. It removes characters that look alike, such as O and 0 or l and 1, which cuts support tickets caused by misread codes.
No. A UUID has a defined structure and version, and version 4 UUIDs are random within that structure. Use the UUID generator when something expects that format specifically.
No. They are generated in your browser and exist only on your screen until you copy them. Reloading the page loses them.
Yes. You can supply a custom alphabet or list characters to exclude, which is useful when a system rejects particular symbols.
If the random string generator is not quite what you need, these other free tools solve closely related problems.
Generate strong random passwords with your own length and character rules.
Generate cryptographically random UUIDs in bulk, with format options.
Produce the standard 32-character MD5 digest of any string in your browser.
Produce the 64-character SHA-256 digest of any string using your browser's own crypto.
Pick random numbers in a range, with unique-only and sorting options.