Random String Lab

Free random string generator

Generate a random character string for passwords, API keys, tokens, or test data — built with crypto.getRandomValues(). No servers, no tracking, no storage.

Random String Generator

Adjustable-length random text from uppercase, lowercase, numbers, and symbols — for passwords, tokens, keys, or anything that needs true randomness.

••••••••••••
16

🔒 This tool runs 100% offline in your browser. We cannot see, save, or transmit anything you generate or type here.

Random String Generation Guide

A random string is a broader idea than a password. It's just a sequence of characters with no pattern, and it shows up everywhere in software beyond login screens. API keys, session tokens, database unique identifiers, temporary file names, test fixtures, and one-time coupon codes all need the same underlying property a password does: nobody should be able to predict the next one from the last one.

Character sets, and why the choice isn't cosmetic

The character set you choose changes what the string is actually useful for, not just how it looks. Letters and numbers only, with no symbols, is the safe default for anything that ends up in a URL, a filename, an environment variable, or a system that might not handle special characters cleanly. An API key with a stray & or # in it can break the very request it's meant to authenticate, since those characters carry meaning in a URL and get misread as part of the structure rather than the key itself. Full character sets including symbols pack more entropy into fewer characters, which matters more for passwords, where a human sometimes still has to type or remember them, than for tokens, where length is nearly free to add and nobody's typing it by hand anyway.

Hexadecimal output (0 to 9 and a to f only) is worth calling out separately, since it's the standard format for things like API secrets, session identifiers, and cryptographic salts in a lot of frameworks and documentation. If you're generating a value to drop into code that expects a hex string specifically, stick to that character set rather than mixing in letters outside a to f, even though this generator can produce them; the receiving system likely won't parse anything else correctly.

How long is long enough, and why it depends on the job

Length requirements vary a lot by purpose, and there's no single right answer the way there almost is for passwords. A session token or API key benefits from being long, 32 characters or more, since it often has a much longer effective lifetime than a login attempt and a higher value if an attacker manages to guess or intercept it: a leaked session token can hand over an active, already-authenticated session without needing a password at all. A short-lived coupon code or a test fixture identifier can be considerably shorter without meaningful risk, since the cost of a lucky guess is low and the value expires quickly anyway. The generator on this page lets you dial the length from 8 to 64 characters and toggle each character category on or off independently, so you can match the output exactly to whatever format the receiving system expects rather than generating something you then have to reformat by hand.

Randomness quality matters as much as length

A string generated from a predictable source, such as a basic pseudo-random function seeded by the current time or a counter, can sometimes be reconstructed by an attacker who knows roughly when or how it was created, even if the string itself looks random on the page. This is a real category of vulnerability in software, not a theoretical one; poorly seeded random generators have led to guessable session tokens and API keys in production systems more than once. This tool uses the Web Crypto API's crypto.getRandomValues(), the same category of cryptographically secure randomness used for encryption keys, drawing on your operating system's secure random source rather than a predictable formula. The output doesn't carry that weakness regardless of what you end up using it for.

Where these strings actually get used

  • API keys and secrets. Usually alphanumeric, often 32 to 64 characters, meant to be stored in an environment variable rather than typed.
  • Session tokens. Long and random by design, since they stand in for a logged-in user for the life of that session.
  • Webhook and signing secrets. Used to verify that a request genuinely came from the service that claims to have sent it, so predictability here defeats the whole point.
  • Database identifiers and test fixtures. Don't need cryptographic strength for their own sake, but benefit from being collision-resistant, which a long random string naturally is.
  • One-time codes and coupon values. Short-lived, so shorter and simpler is usually fine here.

Rotating and storing what you generate

A random string is only as good as how it's handled after you generate it. Treat an API key or secret the way you'd treat a password: never commit it into source control, never paste it into a chat message or a shared document, and store it in an environment variable, a secrets manager, or a password manager's secure notes rather than a plain text file. If a key has been exposed, even briefly, rotating it (generating a fresh one and retiring the old one) is the only real fix; changing your mind about who has access doesn't undo a value that's already been seen.

If what you actually need is something else

If what you need is a login password rather than a token, the strong password generator covers the reasoning behind length and randomness for that specific case, and shows how generation stays entirely in your browser with no server involved. For a short numeric code, use the PIN generator, built for keypads and lock screens rather than software. A phrase you'll need to type by hand, such as a password manager's own master password, is better served by the passphrase generator, since random words are far easier to enter correctly than a string like this one. And if you'd rather have every option, passwords at any length, a passphrase generator, a PIN generator, and a strength checker, on a single page, the all-in-one password generator keeps all of that in one place. For securing specific high-value accounts directly, there are dedicated guides for email passwords, social media passwords, and WiFi network passwords, plus a QR code tool for sharing a WiFi password without typing it out, and the 12 and 15 character generator for forms with a fixed length requirement.

Frequently Asked Questions