Cryptographic commands, not shell tricks

Command-Line Password Generator

Generate high-entropy passwords and tokens from Bash, PowerShell, macOS, Linux, or Windows terminals using operating-system-backed cryptographic randomness.

Choose the command for the required format

  • URL-safe token: use Python secrets.token_urlsafe().
  • Hexadecimal key or token: use openssl rand -hex or Python secrets.token_hex().
  • Base64 random bytes: use openssl rand -base64.
  • Custom password alphabet in PowerShell 7: use .NET RandomNumberGenerator.GetInt32().

Random-byte commands are ideal for software-generated secrets. If a website requires at least one uppercase letter, number, or symbol, use a policy-aware generator instead of editing the output by hand.

OpenSSL password and token commands

OpenSSL asks the operating system for cryptographically secure random bytes and then encodes them. The number after rand is a byte count—not the final number of displayed characters.

24 random bytes as Base64
openssl rand -base64 24

This produces 192 random bits encoded as 32 Base64 characters, followed by a newline. Base64 may include +, /, and padding =, so check the destination's accepted characters.

32 random bytes as hexadecimal
openssl rand -hex 32

This produces 256 random bits as 64 lowercase hexadecimal characters. Hex output is longer because each byte becomes two characters, but it is widely compatible with configuration files and developer secrets.

Python secrets from any terminal

Python's standard-library secrets module is designed for authentication tokens and related secrets. These one-liners work wherever a current Python 3 interpreter is available.

URL-safe token from 24 random bytes
python3 -c 'import secrets; print(secrets.token_urlsafe(24))'
64-character hexadecimal token
python3 -c 'import secrets; print(secrets.token_hex(32))'

On Windows, the launcher may be py instead of python3. For reusable functions, required character groups, and batch generation, see the Python password generator guide.

PowerShell 7 password generator

This PowerShell 7 example selects every character independently with .NET's cryptographically strong RandomNumberGenerator.GetInt32(). Microsoft documents that the method uses discard-and-retry logic to avoid modulo bias.

20 characters from a custom alphabet
$chars = 'abcdefghijkmnopqrstuvwxyzABCDEFGHJKLMNPQRSTUVWXYZ23456789!@#$%^&*'
$password = -join (1..20 | ForEach-Object {
  $chars[[System.Security.Cryptography.RandomNumberGenerator]::GetInt32($chars.Length)]
})
$password

The alphabet omits commonly confused characters while keeping letters, digits, and symbols. Change 1..20 to the required length. Because each position is independent, a particular output is not guaranteed to contain every character class; use the site's custom policy generator when the destination requires class coverage.

Version note: the static GetInt32() method is available with the modern .NET runtime used by PowerShell 7. It is not a portable Windows PowerShell 5.1 one-liner. Do not silently replace it with a time-seeded random function.

Why not use $RANDOM, shuf, or a filtered /dev/urandom pipeline?

Bash's $RANDOM is intended for shell scripting, not secret generation. Commands that filter bytes through tr -dc and stop with head can be easy to copy, but their security and portability are harder to reason about: locale, character filtering, bias, process pipelines, and broken-pipe behavior all matter.

Prefer a high-level cryptographic interface that documents its byte count and encoding. OpenSSL, Python secrets, and .NET RandomNumberGenerator make the random source explicit and avoid inventing a custom shell algorithm.

Bytes, characters, and entropy are different

CommandRandom inputDisplayed lengthAlphabet
openssl rand -base64 2424 bytes / 192 bits32 charactersBase64
openssl rand -hex 3232 bytes / 256 bits64 characters0–9, a–f
secrets.token_urlsafe(24)24 bytes / 192 bitsAbout 32 charactersURL-safe Base64
PowerShell example20 independent selections20 charactersCustom alphabet

Encoding does not add entropy; it represents random bytes with printable characters. Truncating encoded output reduces the possible result space. Request the desired byte count at the source instead.

Verify tools before automating them

Check installed versions
openssl version
python3 --version
$PSVersionTable.PSVersion

Run only the line appropriate to its shell. Confirm the executable path on servers or CI agents, pin dependencies where practical, and test output length and allowed characters. Do not install an unknown password-generator package merely because it has a convenient command name.

Handle terminal output safely

  • A printed password may remain in terminal scrollback, session recording, screen sharing, or CI logs.
  • Do not put a production password directly in a command argument; process listings, job logs, and shell history may expose it.
  • Do not export a password as a long-lived environment variable unless the target workflow explicitly requires it.
  • Avoid world-readable temporary files. Set restrictive permissions before writing and use the approved cleanup workflow.
  • For account creation, transfer the value directly to a trusted password manager.
  • For deployment, prefer the platform's secret manager or credential injection mechanism over plaintext source code.

Frequently asked questions

What is the best command-line password generator?

Use a standard cryptographic API already available in your environment. OpenSSL is convenient for encoded random bytes, Python secrets is portable, and PowerShell 7 can call .NET RandomNumberGenerator.

Can I generate a password in Bash?

Yes, but Bash should orchestrate a cryptographic tool rather than supply the randomness. Call OpenSSL or Python secrets from the shell.

Is PowerShell Get-Random safe for passwords?

PowerShell behavior varies by version. For an auditable password script, call the explicitly documented Get-SecureRandom cmdlet where available or .NET RandomNumberGenerator directly.

How do I generate exactly 20 characters?

Use the PowerShell alphabet example with 1..20, or a policy-aware browser generator. Random-byte encodings produce lengths determined by the encoding.

Should a script guarantee every character class?

Only when the destination requires it. Required classes alter the output distribution and add implementation complexity. Prefer the longest independently random value from an accepted alphabet when possible.

Sources and review scope

Commands and documentation were reviewed on October 4, 2026. Test commands in the exact operating system, shell, OpenSSL build, Python version, and PowerShell runtime used by your workflow.