About
For the values that are not passwords: callback tokens, invite codes, test order numbers, and the fixture data that should not be sequential. Pick a length and an alphabet, and take the result.
How to use
Set the length, choose whether to include letters, digits or both, and generate. Copy it out before you move on, since each press replaces the previous value.
A different job from the password generator
Both draw from the same random source and that is where the similarity ends. A password is typed by a person or a manager into a form that has opinions about punctuation. A token is pasted into a URL, a header, or a filename, where punctuation is what breaks things. Choosing letters and digits is not a weaker choice, it is the right alphabet for where the value is going.
Picking a length that ends the question
Token length is one of those decisions worth over-answering once. Thirty two characters of letters and digits puts a value far outside anything guessable, and the cost of going longer is nothing at all, because no human types it. Short tokens exist because someone was thinking about a column width, and that is the wrong trade for a value that guards something.
Where these are safe to use
Test fixtures, invite codes, callback verification strings, and anything that needs to be unpredictable without being a credential in the strict sense. The line to watch is production secrets: those belong in a secret manager, generated there, so no copy exists in a browser tab, a clipboard, or a chat message where you pasted it to a colleague.
FAQ
How is this different from the password generator?
The alphabet. Passwords want punctuation that people and login forms tolerate. Tokens want characters that survive being put in a URL, a header, or a filename, which usually means letters and digits only.
What random source does it use?
The browser's cryptographic one, the same as the password generator, rather than the ordinary function that only looks random.
How long should a token be?
Thirty two characters of letters and digits is the common default and is comfortably beyond guessing. Go to sixty four when the value has to stay secret for a long time.
Can I use one of these as a production signing key?
For a quick environment, yes. For anything that lives, generate it inside your secret manager, so the value never sits in a browser tab or a shell history in the first place.
Related tools
- Security and generator tools
- Online Notepad
A scratch note kept in your own browser.
- Random Password Generator
Generate a password in the browser, nothing sent.
- Password Strength Checker
Estimate strength locally, nothing leaves the tab.
- SHA Hash Generator
SHA-1, SHA-256 and SHA-512 digests, computed locally.
- Online 2FA Code Generator
Turn a Base32 secret into a 6 digit TOTP code.