What are MySQL password requirements?
MySQL itself does not enforce one universal composition policy. When the optional validate_password component is installed, its variables decide which passwords pass. Without that component, those checks are unavailable. Hosting providers may impose additional rules.
Default MEDIUM policy compatibility
MySQL's documented default MEDIUM policy requires the configured minimum length plus at least one numeric character, one lowercase character, one uppercase character, and one special character. The defaults use an eight-character minimum and one of each category. This tool's default is 24 characters and guarantees every category, but administrators can raise any count.
What STRONG policy adds
STRONG includes the MEDIUM checks and can reject password substrings found in a configured dictionary. A random value from this generator is designed to avoid human words, but only the target MySQL server can evaluate its current dictionary, username check, and customized policy variables.
Connection URL encoding
Connector URLs treat characters such as /, :, @, &, #, =, and ? as structural syntax. The percent-encoded output is the same password represented safely for a URL component. URL-safe mode instead limits symbols to the unreserved set -._~.
Assign and store the password safely
MySQL warns against placing a password directly on a command line because it may briefly remain visible to process-listing tools. Use an interactive password prompt or a protected secret manager. For reusable client login paths, mysql_config_editor prompts without echoing and writes an obfuscated .mylogin.cnf; MySQL notes that this obfuscation is not encryption.
Replication's separate 32-character limit
MySQL's general account passwords are not limited to 32 characters, but the manual documents an effective 32-character limit for passwords used by a replica in CHANGE REPLICATION SOURCE TO; excess characters are truncated. Select 32 or fewer only for that specific workflow.
Official MySQL sources
Policy behavior follows MySQL 8.4's validate_password variables. Credential assignment and the replication limit follow Assigning Account Passwords. URL escaping follows the Connector/J URL syntax.
Related database tools
PostgreSQL password generator provides role-password and PostgreSQL URI guidance. Random key generator creates generic encoded key material. API key generator creates opaque application credentials. Use this page for MySQL account passwords.