What is a temporary password?
A temporary password is an initial or replacement account credential that the receiving system accepts for a limited period or until the first successful sign-in. It is commonly used for employee onboarding, administrator-assisted resets, staged migrations, and controlled test accounts.
Temporary passwords versus one-time passwords
A temporary account password is not the same as a cryptographic one-time password. HOTP and TOTP codes are derived from a shared secret under standards such as RFC 4226 and RFC 6238. This page generates random login credentials; it does not create authenticator-app codes, send SMS messages, or enroll a second factor.
Choose the right profile
Easy-read mode removes 0, O, 1, lowercase l, and uppercase I to reduce transcription mistakes. Alphanumeric mode uses every letter and digit. Full mode adds punctuation when the destination supports it. Longer values reduce the security cost of using a smaller, easier-to-transcribe alphabet.
How to issue temporary credentials safely
- Create the user in the authoritative identity system.
- Set the temporary password and a short server-side expiration.
- Require a password change at first sign-in.
- Deliver the username and password through separate authenticated channels when practical.
- Revoke unused credentials and review successful or failed sign-in events.
Expiry reminders are not enforcement
The optional timestamp is included only to help an administrator track the intended window. Copying a timestamp into CSV does not configure Active Directory, Microsoft Entra, Google Workspace, a database, or any other account system. The authoritative platform must enforce expiration and first-login behavior.
Randomness and handling
Every password is generated with the browser’s cryptographically secure Web Cryptography API and checked for uniqueness within the current batch. Treat the output as sensitive: avoid ordinary email, chat logs, tickets, analytics, screenshots, and source control.