Redis ACL credential

Redis Password Generator

Create lowercase hexadecimal credentials that match the length, rounding, and output format documented for Redis ACL GENPASS.

Generate a Redis ACL password

Redis defaults to 256 bits, producing 64 lowercase hexadecimal characters. Non-multiple-of-four requests are rounded upward.

Choose 1–1024 bits. Use 256 unless your deployment specifies another size.
The leading > tells ACL SETUSER to add this cleartext password and store its SHA-256 hash.

256 requested bits256 emitted bits64 hex characters
Generated locallyThe credential remains in this browser tab. Move it directly into protected Redis configuration.

What does ACL GENPASS generate?

Redis Open Source 6.0 and later provides ACL GENPASS [bits]. Its default output represents 256 random bits as 64 lowercase hexadecimal characters. The browser tool above reproduces that observable format with crypto.getRandomValues(); it does not claim to reproduce Redis's internal HMAC-based pseudorandom implementation.

Why does Redis round the bit count?

Each hexadecimal character represents four bits. Redis therefore rounds the requested value up to the next multiple of four. A five-bit request emits two hexadecimal characters, representing eight emitted bits. The three result labels show the requested bits, actual emitted bits, and output length separately.

Using the password with an ACL user

In an interactive redis-cli session, the rule >password adds a cleartext password to an ACL user; Redis stores its SHA-256 hash. A user can have multiple active passwords, which supports staged rotation. Passwords do not grant permissions by themselves—define only the command, key, and channel rules the application needs.

Do not confuse a password with its stored hash

The generated hexadecimal string is the password itself, not its SHA-256 hash. Redis also accepts a 64-character lowercase hexadecimal hash with a leading #, but hashing an already generated password creates a different value. Use the > rule unless your deployment deliberately provisions precomputed hashes.

Connection URLs and redis-cli

Redis connection URLs use redis://user:password@host:port/db or rediss:// for TLS. Lowercase hexadecimal is URI-unreserved, so this generator's output does not need percent-encoding. Avoid redis-cli -a, which exposes the password as an argument; use --askpass or a protected credential workflow instead.

ACL users versus requirepass

Modern Redis ACLs support named users and scoped permissions. The older requirepass model authenticates the default user only. The same strong random credential can work in either model, but ACL users provide the authorization boundaries applications should use when available.

Managed Redis differences

Redis Software does not expose ACL GENPASS or ACL SETUSER in the same way as Redis Open Source, and Redis Cloud supplies credentials through its management workflow. Use the provider's generated or configured credential rather than assuming this page can issue a valid managed-service password.

Official Redis sources

Format and rounding follow the official ACL GENPASS reference. Password-rule semantics follow ACL SETUSER and the Redis ACL guide. Connection handling follows the official redis-cli documentation.

Related developer tools

Random key generator creates hexadecimal, Base64, and Base64URL key material. API key generator creates opaque application credentials. PostgreSQL password generator creates database role passwords. Use this page when Redis ACL compatibility is the goal.