Random String Generator
Generate random strings of 1–256 characters from the character sets you choose, with pool size and entropy in bits. Uses your browser's secure random source.
Worked examples
- A 32-character alphanumeric string
A general-purpose token for a test fixture, API key placeholder or salt: 62 possible characters, about 190 bits.
- Five hex-style lowercase codes
Turning off the letter sets and adding extra characters builds a custom pool; this one is the 16 hexadecimal digits.
- Readable codes without look-alike characters
Dropping 0, O, 1 and I from uppercase letters plus digits leaves 32 characters, which suits coupon or invite codes people type by hand.
What this tool does
This tool produces random strings from the character classes you switch on: uppercase letters, lowercase letters, digits and symbols, plus any extra characters you type in. Length runs from 1 to 256 characters and you can generate up to 50 strings at once. Alongside the output it shows the size of the character pool and the entropy of each string in bits, so you can judge whether a string is strong enough for its job.
When you need it
- Test fixtures, seed data and placeholder tokens for development environments.
- Salts, nonces, API key placeholders and secrets for local config files.
- Coupon, invite or reference codes, with look-alike characters removed so they survive being read aloud or typed from a printout.
- Any case where
Math.random().toString(36)would be tempting, and you would rather have something with real entropy.
How the strings are generated
Each position is chosen independently and uniformly from the pool. The randomness comes from crypto.getRandomValues, the browser's cryptographically secure generator. Picking a random character from a pool that is not a power of two is where many generators go wrong. Taking a random number and applying % poolSize favors the first few characters, because the range of the random number does not divide evenly. This tool uses rejection sampling on a 32-bit random value: any value in the leftover tail that would cause bias is thrown away and redrawn, so every character in the pool is exactly equally likely.
Duplicates are removed from the pool before generation. If you type an extra character that is already enabled by one of the toggles, it does not become more likely than the others, and the pool size and entropy stay honest.
The entropy figure
Entropy in bits is length × log2(pool size). A 32-character string from the 62 letters and digits has 32 × log2(62) ≈ 190.5 bits. A 12-character hex string has 12 × 4 = 48 bits. This is the entropy of the generation process, assuming a guesser knows your settings, which is the safe assumption. As a rough guide, 128 bits or more is comfortable for keys and tokens that must resist offline guessing, around 64 bits is enough for tokens that are rate-limited, and anything in the 30s is a code that a database uniqueness check has to protect.
Excluding ambiguous characters shrinks the pool. The option removes 0, O, o, 1, l, I and |, taking the 62 alphanumerics to 56 and reducing each character from about 5.95 bits to 5.81. For human-typed codes this is almost always worth it; lengthen the string slightly to compensate.
What it does not do
- It does not guarantee at least one character of each class. Each position is independent, so a short string with every class enabled can lack a digit or symbol. Forcing one of each class changes the distribution and would make the entropy shown inexact. If a site demands a digit and a symbol, regenerate, or use a longer string.
- It is not pronounceable and does not avoid accidental words.
- Nothing is sent anywhere, but a string on screen is visible to anyone looking at the screen and may be kept by clipboard managers. For long-lived credentials, generate them in a password manager.
The symbol set
When symbols are on, the pool adds !@#$%^&*()-_=+[]{};:,.<>?/, 26 characters chosen to be valid in most config files and shells with quoting. If a target system rejects some of them, leave symbols off and add a custom set in the extra-characters field. The extra field accepts up to 64 characters, including non-ASCII, and each Unicode character counts as one pool member.
Because every run is random, the examples on this page show settings rather than fixed results.
Frequently asked questions
- How is the entropy figure calculated?
- Entropy in bits is length × log2(pool size), where the pool is the number of distinct characters you enabled. It assumes each character is drawn independently and uniformly, which is how this tool generates them. A 32-character string from a 62-character pool has 32 × log2(62) ≈ 190.5 bits.
- Is it safe to use these as passwords or API keys?
- The characters come from crypto.getRandomValues, the browser's cryptographically secure source, and are selected without modulo bias, so the output is suitable for secrets provided the entropy is high enough (128 bits or more is a common target for keys). Everything runs locally, but consider using a password manager for anything you will store long-term.
- Why does excluding ambiguous characters lower the entropy?
- It shrinks the pool: removing 0, O, o, 1, l, I and | takes the 62 alphanumerics down to 56, which cuts roughly 0.15 bits per character. For a typed code the readability is usually worth it; lengthen the string to compensate.
- Does the generator guarantee at least one character of each type?
- No. Each position is drawn independently from the whole pool, so a short string with every set enabled can occasionally lack a digit or symbol. Forcing one of each type would make the output slightly less random, so the entropy shown would no longer be exact. If a site demands one of each class, regenerate or use a longer string.