BasicApps Logo
Random String Generator | Passwords & Tokens | BasicApps

Generate cryptographically secure random strings for passwords, tokens, and testing

Common Use Cases

API Key32 chars, hex
Session ID24 chars, safe
Password16 chars, alphanumeric
Token64 chars, hex
File Name12 chars, safe
PIN Code6 chars, numbers

Pick your character set first — that decision matters more than length

A 20-character string built from just lowercase letters has far less entropy than a 12-character string using uppercase, lowercase, digits, and symbols. The character pool size is what drives unpredictability. For passwords that'll be typed by humans — not stored in a password manager — you might want to exclude symbols like 0, O, I, l that look identical depending on the font. For machine-to-machine tokens where a human never types them, enable everything and use maximum length.

The difference between "random" and "cryptographically random" is that normal random functions in most programming languages are seeded from predictable sources and their output can be predicted if you know the seed or observe enough prior output. This tool uses the browser's built-in cryptographic random source — the same one used for generating TLS keys — so there's no seed to guess.

Bulk mode generates multiple strings at once

If you need a hundred test user passwords for seeding a dev database, or a list of unique identifiers for a batch import, the bulk option outputs them as a newline-separated list you can copy straight into a spreadsheet or script. Each one is independently generated — there's no sequence or relationship between them. That's what you want. Predictable patterns between tokens are a vulnerability even when each individual token looks random.