ByToolHub
All tools

Security & identity

Hashes, passwords and identifiers, produced by your own browser's cryptographic random source.

A password generator on a website asks for a particular kind of trust, and it is worth being precise about what earns it. These tools use the Web Crypto API — the same primitive that generates encryption keys — and run wholly inside the page. Nothing is sent, nothing is logged and nothing survives a refresh, which you can verify by disconnecting from the internet after the page loads and generating again.

That still leaves a judgement call. For a password you will actually rely on, the generator built into your password manager or operating system is the most cautious choice, because it removes the browser tab from the question entirely. For a checksum, a test fixture, or a batch of identifiers for a database, these are exactly the right tool.

3 tools in security & identity

Which one do you need?

You need a password that passes a site's rules
The password generator guarantees at least one character from every type you enable, reports genuine entropy in bits rather than a made-up strength score, and can exclude look-alike characters like O, 0, I and l for anything you will type by hand.
You want to check a download hasn't been altered
The hash generator produces MD5, SHA-1, SHA-256, SHA-384 and SHA-512 from text or a file. Compare the result to the checksum the publisher lists — if they match, the bytes are identical.
You need unique IDs for rows, files or test data
The UUID generator makes random v4 or time-ordered v7 identifiers in bulk, in uppercase, no-dash, braces or URN format. Use v7 when the IDs become database keys, because they sort by creation time.

Guides for these tools

Frequently asked questions

Are the passwords really random?

They come from crypto.getRandomValues, the browser's cryptographically secure random source, and the selection uses rejection sampling so that no character is more likely than another — a plain modulo would quietly bias the alphabet. The entropy figure shown is calculated from the alphabet size and length, so it is a real measurement rather than a rating.

Should I still use MD5?

Only for non-security checks like detecting an accidentally duplicated file. MD5 and SHA-1 are both broken for anything adversarial — collisions can be constructed deliberately — so use SHA-256 whenever the question is whether someone tampered with the data. Neither belongs anywhere near password storage, which needs a deliberately slow function like bcrypt or Argon2.

Is anything I generate here stored or recoverable?

No. There is no database and no server-side component to these tools. Once you close or refresh the page, whatever was generated is gone — copy it somewhere safe before you navigate away.

Other kinds of tool