Choose the command for the required format
- URL-safe token: use Python
secrets.token_urlsafe(). - Hexadecimal key or token: use
openssl rand -hexor Pythonsecrets.token_hex(). - Base64 random bytes: use
openssl rand -base64. - Custom password alphabet in PowerShell 7: use .NET
RandomNumberGenerator.GetInt32().
Random-byte commands are ideal for software-generated secrets. If a website requires at least one uppercase letter, number, or symbol, use a policy-aware generator instead of editing the output by hand.
OpenSSL password and token commands
OpenSSL asks the operating system for cryptographically secure random bytes and then encodes them. The number after rand is a byte count—not the final number of displayed characters.
openssl rand -base64 24This produces 192 random bits encoded as 32 Base64 characters, followed by a newline. Base64 may include +, /, and padding =, so check the destination's accepted characters.
openssl rand -hex 32This produces 256 random bits as 64 lowercase hexadecimal characters. Hex output is longer because each byte becomes two characters, but it is widely compatible with configuration files and developer secrets.
Python secrets from any terminal
Python's standard-library secrets module is designed for authentication tokens and related secrets. These one-liners work wherever a current Python 3 interpreter is available.
python3 -c 'import secrets; print(secrets.token_urlsafe(24))'python3 -c 'import secrets; print(secrets.token_hex(32))'On Windows, the launcher may be py instead of python3. For reusable functions, required character groups, and batch generation, see the Python password generator guide.
PowerShell 7 password generator
This PowerShell 7 example selects every character independently with .NET's cryptographically strong RandomNumberGenerator.GetInt32(). Microsoft documents that the method uses discard-and-retry logic to avoid modulo bias.
$chars = 'abcdefghijkmnopqrstuvwxyzABCDEFGHJKLMNPQRSTUVWXYZ23456789!@#$%^&*'
$password = -join (1..20 | ForEach-Object {
$chars[[System.Security.Cryptography.RandomNumberGenerator]::GetInt32($chars.Length)]
})
$passwordThe alphabet omits commonly confused characters while keeping letters, digits, and symbols. Change 1..20 to the required length. Because each position is independent, a particular output is not guaranteed to contain every character class; use the site's custom policy generator when the destination requires class coverage.
GetInt32() method is available with the modern .NET runtime used by PowerShell 7. It is not a portable Windows PowerShell 5.1 one-liner. Do not silently replace it with a time-seeded random function.Why not use $RANDOM, shuf, or a filtered /dev/urandom pipeline?
Bash's $RANDOM is intended for shell scripting, not secret generation. Commands that filter bytes through tr -dc and stop with head can be easy to copy, but their security and portability are harder to reason about: locale, character filtering, bias, process pipelines, and broken-pipe behavior all matter.
Prefer a high-level cryptographic interface that documents its byte count and encoding. OpenSSL, Python secrets, and .NET RandomNumberGenerator make the random source explicit and avoid inventing a custom shell algorithm.
Bytes, characters, and entropy are different
| Command | Random input | Displayed length | Alphabet |
|---|---|---|---|
openssl rand -base64 24 | 24 bytes / 192 bits | 32 characters | Base64 |
openssl rand -hex 32 | 32 bytes / 256 bits | 64 characters | 0–9, a–f |
secrets.token_urlsafe(24) | 24 bytes / 192 bits | About 32 characters | URL-safe Base64 |
| PowerShell example | 20 independent selections | 20 characters | Custom alphabet |
Encoding does not add entropy; it represents random bytes with printable characters. Truncating encoded output reduces the possible result space. Request the desired byte count at the source instead.
Verify tools before automating them
openssl version
python3 --version
$PSVersionTable.PSVersionRun only the line appropriate to its shell. Confirm the executable path on servers or CI agents, pin dependencies where practical, and test output length and allowed characters. Do not install an unknown password-generator package merely because it has a convenient command name.
Handle terminal output safely
- A printed password may remain in terminal scrollback, session recording, screen sharing, or CI logs.
- Do not put a production password directly in a command argument; process listings, job logs, and shell history may expose it.
- Do not export a password as a long-lived environment variable unless the target workflow explicitly requires it.
- Avoid world-readable temporary files. Set restrictive permissions before writing and use the approved cleanup workflow.
- For account creation, transfer the value directly to a trusted password manager.
- For deployment, prefer the platform's secret manager or credential injection mechanism over plaintext source code.
Frequently asked questions
What is the best command-line password generator?
Use a standard cryptographic API already available in your environment. OpenSSL is convenient for encoded random bytes, Python secrets is portable, and PowerShell 7 can call .NET RandomNumberGenerator.
Can I generate a password in Bash?
Yes, but Bash should orchestrate a cryptographic tool rather than supply the randomness. Call OpenSSL or Python secrets from the shell.
Is PowerShell Get-Random safe for passwords?
PowerShell behavior varies by version. For an auditable password script, call the explicitly documented Get-SecureRandom cmdlet where available or .NET RandomNumberGenerator directly.
How do I generate exactly 20 characters?
Use the PowerShell alphabet example with 1..20, or a policy-aware browser generator. Random-byte encodings produce lengths determined by the encoding.
Should a script guarantee every character class?
Only when the destination requires it. Required classes alter the output distribution and add implementation complexity. Prefer the longest independently random value from an accepted alphabet when possible.
Sources and review scope
Commands and documentation were reviewed on October 4, 2026. Test commands in the exact operating system, shell, OpenSSL build, Python version, and PowerShell runtime used by your workflow.