PASSWORD GENERATOR BY HTTPS.CL

API access, quick links, local password generation.

PASSWORD GENERATOR01
0464
CHARACTER SETS
$
API / QUICK LINKS02

Open a quick link to create a new password locally in your browser.

/p/15/all15 is the length. all includes lowercase, uppercase, numbers and symbols. The page shows only the password, generated with Web Crypto in your browser and never sent to the server.

Every visit creates a new password. The link stores options, never a password.

Use /p/15/all.txt only when you need a server-generated raw-text response for a script.

02 / API — PLAIN TEXT

Use format=text when a script needs only the password. API passwords are generated on the server.

REQUEST
curl 'https://random.https.cl/api/v1/password?length=15&sets=all&format=text'
EXAMPLE RESPONSE — NEVER REUSE
mR7!qZ2#kLp9@XaT5uV?

You can also request plain text with the standard HTTP header:

REQUEST
curl -H 'Accept: text/plain' 'https://random.https.cl/api/v1/password?length=15&sets=all'

03 / API — JSON

JSON is the default when format=text and Accept: text/plain are omitted.

REQUEST
curl 'https://random.https.cl/api/v1/password?length=15&sets=all'
EXAMPLE RESPONSE — NEVER REUSE
{
  "password": "mR7!qZ2#kLp9@XaT5uV?",
  "length": 20,
  "sets": ["lower", "upper", "digit", "symbol"]
}

04 / PARAMETERS AND CHARACTER SETS

length
Integer from 1 to 256. Default: 16.
sets
Comma-separated character sets. Default: all.
format
text for plain text. JSON is the default.
lowerabcdefghijkmnopqrstuvwxyz
upperABCDEFGHJKLMNPQRSTUVWXYZ
digit23456789
symbol!@#$%*-_=+?
alllower + upper + digit + symbol
alnumlower + upper + digit

At least one character from every selected set is guaranteed. length must therefore be at least the number of selected sets.

05 / BEHAVIOR AND ERRORS

  • No authentication is required.
  • Every API request creates a new password on the server.
  • The main generator and quick links create passwords locally in your browser.
  • Quick links ending in .txt and every API request create passwords on the server.
  • Responses use Cache-Control: no-store, private.
  • Invalid parameters return HTTP 400 with JSON {"error":"..."}, including requests for plain text.