Random token generator
Generate uniformly random tokens or passwords with crypto.getRandomValues plus rejection sampling, with charset options, length, batch count and a strength estimate.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
What this tool does
- Generate API keys, session IDs, invite codes or one-time passwords — several at a time, ready to paste into a config.
- For passwords someone has to read aloud or copy by hand, enable "exclude ambiguous characters" to drop 0 O 1 l I and remove a whole class of mistakes.
- Compose the charset yourself: upper and lower case, digits, symbols, plus custom characters such as the URL-safe -_ pair.
- See the charset size and entropy before generating, so "is 16 characters enough?" becomes a number instead of a hunch.
Example
Input
Length 24, count 3, upper + lower case and digits, ambiguous characters excluded
Output
Charset size: 57 Entropy: about 140.0 bits (very strong) Sample tokens: cUyJ9UXbgiJ5DHRtTXvWxh8G k4ekvEjEZRt7WemGZib5EWZo 4Epxb4T9PDTM26c4gAVvcWCB
The tokens themselves differ on every run — the lines above are just one sample. The charset size and entropy are reproducible (57 = 62 − 5).
Frequently asked questions
Is this actually random, and is it safe enough?
It uses the browser's crypto.getRandomValues, which is a cryptographically secure source rather than Math.random. Characters are also chosen with rejection sampling: for a charset of size n only bytes in [0, floor(256/n)×n) are accepted before taking the modulo, so every character has exactly the same probability and modulo bias is impossible.
How many characters are enough?
Read the entropy: below 45 bits is labelled weak, 45–70 fair, 70–100 strong and above 100 very strong. Upper case plus lower case plus digits at 16 characters is about 95 bits, which is fine for everyday use; go for 24 characters or more for important credentials.
Why is the charset size smaller than the boxes I ticked?
Characters are deduplicated. A custom character that is already included (adding another a, say) does not enlarge the charset, and "exclude ambiguous characters" removes five more (0 O 1 l I). That is how 62 becomes 57.
Can the custom characters contain a space?
No — spaces are ignored, because a token containing spaces is very easily truncated when copied and pasted. Every other printable character can be added.
Are generated tokens stored or uploaded?
No. The randomness comes from your local browser crypto API, the tokens live only in this page's memory, nothing is sent to a server and nothing is written to localStorage. Reloading the page discards them, so copy what you need first.
Keywords:tokenpasswordrandomgenerator令牌密码随机安全cryptoentropy