What makes a password PostgreSQL-compatible?
PostgreSQL accepts a role password as a nonempty string and does not publish one global minimum length or required mix of uppercase, lowercase, digits, and symbols. Hosting platforms and organizational policy may add their own rules. This generator applies strong defaults without presenting them as PostgreSQL requirements.
URI-safe and full-symbol modes
URI-safe mode uses letters, digits, and the RFC 3986 unreserved symbols -._~, so the result can be placed in a properly structured connection URI without reserved-character ambiguity. Full-symbol mode expands the alphabet. The second output percent-encodes reserved characters so it can be used as the password component of a PostgreSQL URI.
Use SCRAM-SHA-256 authentication
PostgreSQL 18 describes SCRAM-SHA-256 as its most secure available password method. The older MD5-encrypted password method is deprecated and scheduled for removal. The generated password is cleartext input for the role-setting workflow; it is not itself a SCRAM verifier or stored hash.
Set the password without leaking it into history
PostgreSQL warns that an unencrypted password embedded in CREATE ROLE or ALTER ROLE may be transmitted in cleartext and logged in client history or server logs. In psql, run \password role_name and provide the value through its prompt instead of pasting a cleartext password into a SQL statement.
Connection URI encoding matters
A URI has the form postgresql://user:password@host:5432/database. Characters such as @, :, /, ?, #, and % have structural meanings. Use the percent-encoded output when full-symbol mode is selected. Encoding changes the URI representation, not the underlying password PostgreSQL receives.
Storage and rotation
Give every role and environment a unique password. Store it in a deployment secret manager or protected runtime configuration, never in source control. Rotate exposed credentials immediately and update every dependent service atomically enough to avoid an extended outage.
Official PostgreSQL sources
Authentication recommendations follow PostgreSQL 18's password authentication documentation. Safe role-password handling follows the ALTER ROLE warning. URI encoding follows the official libpq connection URI documentation.
Related tools
MySQL password generator creates policy-aware database account credentials. Random key generator creates generic encoded key material. API key generator creates opaque application credentials. Laravel APP_KEY generator creates that framework's exact Base64 format. Use this page for PostgreSQL login-role passwords.