Is this actually cryptographically secure, or just Math.random()?
Cryptographically secure — every character comes from the Web Crypto API's crypto.getRandomValues(), with rejection sampling to avoid modulo bias, not Math.random().
Unioned with the character types above (duplicates are ignored so every character stays equally likely).
Generated strings will appear here.
Generate cryptographically secure random strings with custom character sets.
Random strings are generated locally in your browser using the Web Crypto API and never sent anywhere.
Cryptographically secure — every character comes from the Web Crypto API's crypto.getRandomValues(), with rejection sampling to avoid modulo bias, not Math.random().
This is built for general-purpose random strings — tokens, test data, IDs, cache keys — with more character-set flexibility, including a custom-characters field. The Password Generator is tuned specifically for human-usable passwords and passphrases.
Yes — toggle Exclude ambiguous to drop easily-confused characters from the output.
Up to 50 per batch — pick 1, 5, 10, 20, or 50, each up to 256 characters long.
Not as a built-in preset, but the custom-characters field gets you there — type 0-9a-f for hex, or your own alphabet for anything else. It's merged with any built-in sets you also enable.
No — entirely client-side.