Random String Generator
Make up to 15 random strings of 1–100 characters from any mix of lowercase, uppercase, digits and symbols, each with a copy button.This random string generator builds strings of any length from 1 to 100 characters, up to 15 at a time, from whichever character classes you tick: lowercase letters, uppercase letters, digits and symbols. Every character is drawn independently, so nothing about a string depends on the one before it. Each result comes with a copy button. It is meant for developers and testers who need filler values, IDs, tokens or sample input, not as a password manager.
Settings
- Number of strings. 1 to 15 per click. All of them use the same length and character settings.
- String length. 1 to 100 characters. The default is 25.
- Character classes. Four checkboxes: lowercase (a–z, 26 characters), uppercase (A–Z, 26), digits (0–9, 10) and symbols (29 characters:
!@#$%^&*()_+~`|}{[]:;?><,./-=). You can turn any of them off, but the form will not let you uncheck the last remaining class, so there is always at least one pool to draw from.
With all four boxes ticked the pool is 91 characters. A 25-character string from that pool has roughly 9125 possible values, which is more than enough for unique test IDs. Note that there is no "no repeats" option: a string can contain the same character several times, and with a pool this size that is expected.
How the strings are made
The generator runs entirely in your browser. It concatenates the selected character sets into one pool, then for each position picks an index with JavaScript's Math.random(). That is fine for test data, placeholder content, nonces in demos, or seeding fixtures. It is not a cryptographically secure source, so do not use the output for real passwords, session tokens, signing keys or anything that protects an account. For key-shaped output produced with a proper random source, use the Encryption Key Generator; for realistic vendor-style keys for mocking, the Random API Key Generator is a better fit.
What people use it for
- Test fixtures. Fill a username, slug or note field with a 12-character alphanumeric value to check validation, truncation and encoding. Untick symbols if the field must be URL-safe.
- Boundary testing. Set the length to 100 and generate 15 strings to see how a form or API behaves at its maximum input size.
- Placeholder identifiers. Temporary order numbers, coupon-style codes or record IDs for screenshots and mock data. If you need codes in a fixed pattern such as XXXX-XXXX, the Random Code Generator does that.
- Salts and nonces for local experiments. A quick 32-character string for a hashing demo or a cache-buster query parameter.
- Typing practice. Symbol-heavy 40-character strings are a decent drill for the keys you rarely hit.
Choosing the right character set
Which boxes to tick depends on where the string is going:
- Lowercase + digits is the safest for anything that ends up in a URL, filename, hostname or case-insensitive database key (the pool is 36 characters, like base36).
- Lowercase + uppercase + digits gives a 62-character pool, the same alphabet as base62 short links and YouTube-style IDs. A 22-character string from this pool carries about 131 bits of entropy.
- All four classes is the right choice when you want to stress-test escaping. The symbol set includes quotes, angle brackets, braces, backticks and a forward slash, exactly the characters that break naive HTML, SQL and shell handling.
- Digits only produces numeric strings that may start with 0, which is useful for PIN-shaped test values (but use a dedicated tool if you need real number formats).
Other generators for developer data, such as the Random MAC Address Generator, Random IP Generator and Random Email Generator, are listed under all developer & test data tools.
Frequently asked questions
- What is the maximum string length?
100 characters per string, and up to 15 strings per click. Set the length field to 100 and the count to 15 to get the largest batch.
- Can I generate letters only, or numbers only?
Yes. Untick the classes you don't want. For letters only, uncheck Digits and Symbols; for numbers only, leave just Digits checked. The form always keeps at least one class selected.
- Is this safe to use for passwords?
Not for anything important. The strings are made with Math.random(), which is not a cryptographic random source. Use a password manager or a tool built on a secure random generator for real credentials.
- Are the strings stored or sent anywhere?
No. Generation happens in your browser and nothing is uploaded. Once you leave or regenerate, the previous strings are gone, so copy what you need.
- Can the same string be generated twice?
In theory, but for strings of 8 or more characters from the full pool the odds are negligible. Very short strings (1 to 3 characters) from a small pool will repeat often.



