🎲 Random String Generator
General-purpose random strings — useful for test data, temporary IDs, or anywhere you need a random value that isn't a password. Define your own character set below.
Pool size drives everything
Whatever you type in the character set box is de-duplicated first, so
aaab is a pool of two and the reported bits stay honest. Each
position is then an independent draw with rejection sampling:
bits = length x log2(pool)
12 x log2(62) = 12 x 5.9542 = 71 bits
50% chance of a collision after ~1.18 x sqrt(pool^length)
62^12 = 3.2 x 10^21 -> 67 billion strings
That second line is the one that matters for identifiers. Eight alphanumeric characters is 48 bits, with even odds of a duplicate after just 17 million strings - close enough to bite a busy table.
The presets, and one thing to watch
- Alphanumeric is 62 characters, lowercase 26, digits 10.
- Hex loads
0123456789ABCDEFabcdef- 22 distinct characters, both cases of A-F. Output is mixed case and worth 4.46 bits a character rather than a clean 4. Delete the uppercase run if you need canonical hex that will compare equal elsewhere. - The box accepts anything you paste, so you can strip lookalikes or restrict output to what a legacy field tolerates.
Frequently asked questions
How long should a random ID be to avoid collisions?
Work backwards from how many you will mint. For a billion ids at a one in a million chance of any clash you need about 79 bits, which is 14 alphanumeric characters; 16 characters gives 95 bits and ends the conversation.
Does repeating a character in the set make it more likely?
No. The set is de-duplicated before generation, so aab behaves
exactly like ab. You cannot weight a character by repeating it,
which is deliberate - it keeps the bit count true.
Are these strings random enough for a session token?
The source is crypto.getRandomValues, so yes if they are long
enough - 128 bits, or 22 alphanumeric characters, is the usual bar. Pasting them
in by hand is the weak part, not the randomness.