Task path / input to outcome
How to generate a strong random password
- 01
Set the password length
Set a length from 8 to 128 characters (default 24) and choose the character sets. The bit figure is a theoretical upper bound from the length and alphabet, not a strength score. Changing the settings clears the previous result.
- 02
Choose the character sets
Under Character sets, toggle Lowercase a–z, Uppercase A–Z, Digits 0–9, and Symbols — a 23-character set covering !@#$%^&*()-_=+[]{};:,.? and friends. At least one set must stay enabled, and every selected set is guaranteed to appear in the password at least once before shuffling. When a target system restricts symbols, turn that set off rather than regenerating until the output happens to comply.
- 03
Generate the password
Press Generate password. Web Crypto and rejection sampling select one character from each enabled set, fill the remaining positions from the combined alphabet, then shuffle with Fisher–Yates. Every selected set appears at least once; complete passwords are not sampled uniformly from all valid combinations.
- 04
Copy or download the secret
Use Copy output to place the password on the system clipboard and paste it into a password manager; clear the clipboard according to your device's policy. Download saves toolars-strong-password.txt as unencrypted plain text, so protect or remove that file after saving the password. Generation itself runs in this tab without an upload. Reset clears the workspace result but cannot revoke copies already placed on the clipboard, disk, or another app.
- 05
Create or verify a Bcrypt password hash
Use the generated secret or enter another password, choose cost 4 through 12, and create or verify a real Bcrypt hash in the isolated Worker. Passwords over 72 UTF-8 bytes are rejected instead of silently truncated.