Generators

Random String Generator

Random Strings

Generate a Random String

Set the length and character sets to build secure random strings, tokens, or keys.

Quick Presets


Length: 16 characters


No random strings generated yet

Configure your settings above and click Generate Random Strings to create secure strings.

Tool features

Secure random string generation with full customization
4 features

Cryptographically Secure

Uses secure random generation algorithms

Customizable Sets

Choose from letters, numbers, symbols, or custom chars

Bulk Generation

Generate up to 100 strings at once

Multiple Presets

Quick presets for passwords, tokens, and more

What is a secure random string & how it works

Why the random source matters as much as the length

A random string is only as strong as the randomness behind it. Tokens, passwords, invite codes and test data all need characters that an attacker cannot predict, which means a cryptographically secure random number generator rather than a general-purpose one like Math.random().

This generator draws from Node.js crypto.randomBytes and maps the bytes onto the character sets you choose. Strength grows with both length and alphabet size: each character from a 62-symbol set adds about 5.95 bits, so a 22-character alphanumeric string carries roughly 128 bits.

Entropy
Length × log2(alphabet size); 128 bits resists brute force.
Character set
Uppercase, lowercase, digits and symbols; more types, more bits per character.
CSPRNG
A cryptographically secure random generator whose output cannot be predicted.

How to use this tool

Generate random strings in four steps
1
Pick a preset or sets
Start from a preset or choose uppercase, lowercase, digits and symbols yourself.
2
Set length and quantity
Choose how long each string is and how many to generate.
3
Generate
Create the strings from a secure random source.
4
Copy the results
Copy a single string, or copy the whole list at once.

Frequently asked questions

Common questions about random strings
5 Q&A

For secrets such as API tokens or reset links, aim for 128 bits of entropy: about 22 alphanumeric characters or 32 hex characters.

They are generated with a cryptographically secure source, so yes. Strings are generated on the ShowDNS server and not stored; for your most sensitive credentials, a password manager’s built-in generator avoids any network transfer.

Symbols add strength per character, but many systems restrict them. If a site rejects symbols, make the string longer instead.

Math.random() is a fast pseudo-random generator whose output can be predicted after observing enough values. Use crypto.getRandomValues() in browsers or crypto.randomBytes() in Node.js.

Excluding look-alikes such as 0/O and 1/l makes codes easier to read aloud or type, at a small cost in entropy per character; add a few characters to compensate.