PostgreSQL role credential

PostgreSQL Password Generator

Create a strong random password for a PostgreSQL login role. Choose a connection-URI-safe alphabet or broader symbols with a ready-to-copy percent-encoded value.

Generate a PostgreSQL role password

PostgreSQL does not impose a universal composition rule. This tool defaults to 24 random characters and guarantees uppercase, lowercase, digits, and a symbol.

Choose 16–128 characters.
Full symbols may require percent-encoding in a connection URI.
Insert this encoded component after postgresql://user:, not the raw full-symbol password.

24 charactersURI-safe alphabet145.1 random bits
Generated locallyThe password remains in this browser tab. Move it directly into protected database configuration.

What makes a password PostgreSQL-compatible?

PostgreSQL accepts a role password as a nonempty string and does not publish one global minimum length or required mix of uppercase, lowercase, digits, and symbols. Hosting platforms and organizational policy may add their own rules. This generator applies strong defaults without presenting them as PostgreSQL requirements.

URI-safe and full-symbol modes

URI-safe mode uses letters, digits, and the RFC 3986 unreserved symbols -._~, so the result can be placed in a properly structured connection URI without reserved-character ambiguity. Full-symbol mode expands the alphabet. The second output percent-encodes reserved characters so it can be used as the password component of a PostgreSQL URI.

Use SCRAM-SHA-256 authentication

PostgreSQL 18 describes SCRAM-SHA-256 as its most secure available password method. The older MD5-encrypted password method is deprecated and scheduled for removal. The generated password is cleartext input for the role-setting workflow; it is not itself a SCRAM verifier or stored hash.

Set the password without leaking it into history

PostgreSQL warns that an unencrypted password embedded in CREATE ROLE or ALTER ROLE may be transmitted in cleartext and logged in client history or server logs. In psql, run \password role_name and provide the value through its prompt instead of pasting a cleartext password into a SQL statement.

Connection URI encoding matters

A URI has the form postgresql://user:password@host:5432/database. Characters such as @, :, /, ?, #, and % have structural meanings. Use the percent-encoded output when full-symbol mode is selected. Encoding changes the URI representation, not the underlying password PostgreSQL receives.

Storage and rotation

Give every role and environment a unique password. Store it in a deployment secret manager or protected runtime configuration, never in source control. Rotate exposed credentials immediately and update every dependent service atomically enough to avoid an extended outage.

Official PostgreSQL sources

Authentication recommendations follow PostgreSQL 18's password authentication documentation. Safe role-password handling follows the ALTER ROLE warning. URI encoding follows the official libpq connection URI documentation.

Related tools

MySQL password generator creates policy-aware database account credentials. Random key generator creates generic encoded key material. API key generator creates opaque application credentials. Laravel APP_KEY generator creates that framework's exact Base64 format. Use this page for PostgreSQL login-role passwords.