Generate secure credentials without sending anything to a server
Passwords, OTPs, UUIDs and hashes are all generated using your browser's built-in cryptographically secure random number generator and hashing functions — meaning the values you create here never travel over the network.
What's included
- Password Generator — a random password of any length using a wide character set, automatically copied to your clipboard.
- OTP Generator — a random 6-digit one-time code, useful for testing flows that need a sample OTP.
- UUID v4 / NanoID — unique identifiers for development, databases or testing.
- Hash Generator — SHA-256, SHA-384, SHA-512, SHA-1 and MD5 hashes of any text.
- Hash Compare — quickly check whether two hash strings match.
Is MD5 still considered secure?
MD5 is widely considered cryptographically broken for security purposes like password storage, though it's still commonly used for basic checksums and file integrity checks where collision resistance isn't critical.
Are generated passwords stored anywhere?
No — each password is generated fresh in your browser and copied to your clipboard, with nothing logged or saved beyond that.
What's the difference between a UUID and a NanoID?
Both generate unique identifiers, but UUID v4 follows a fixed 36-character standard format widely used in databases, while NanoID is shorter and URL-friendly, often preferred for use in web links.
Can I verify that a file wasn't tampered with using the hash generator?
Yes — generate a SHA-256 hash of the file content and compare it against a known-good hash using Hash Compare; any difference means the content has changed.
Using this in a Central Government office
A hash is a short fingerprint of a file. Two files with the same hash are the same file; a single changed byte produces a completely different hash. That property answers one specific and occasionally important question: did this document change between being sent and being received?
Where this comes up
- Confirming a received document is the one that was sent, when it matters that nothing was altered in transit.
- Recording the state of a document at a point in time, so a later claim that it was modified can be tested.
- Checking a download against a checksum published alongside it.
What a hash does not do
It is not a signature and carries no authentication. A hash tells you a file has not changed; it tells you nothing about who created it or whether they had authority to. Anyone can compute a hash of a document they have altered and publish that instead. For anything requiring authenticity rather than integrity — an order, an approval, a return — a digital signature under the Information Technology Act is the appropriate instrument, not a checksum.
Note also that hashing is exact and unforgiving: re-saving a PDF, adding a comment, or opening and closing it in some applications changes the file and therefore the hash, even though the visible content is identical.