NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #2254 most downloaded on NuGet
A cross-platform .NET library that generates cryptographically secure random passwords, passphrases, OTPs, API keys and readable identifiers. Configurable via a fluent API, presets (OWASP/NIST) and dependency injection, with async support and entropy estimation.
Last release 4 months ago
29 May 2026
Release timing varies
gaps range from 2 weeks to 4.4 years
Most releases are documented
notes for 8 of 13 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
15 releases · first in 2016
3.0.0 is a major release: cryptographically secure RNG with unbiased sampling, exception/TryNext error handling, async APIs, dependency-injection supp
3.0.0 is a major release: cryptographically secure RNG with unbiased sampling, exception/TryNext error handling, async APIs, dependency-injection support, presets (OWASP/NIST/OTP/API key/passphrase), custom pools, exclude-ambiguous, per-class minimums and entropy estimation. See the migration guide for upgrading from 2.x.
The v2 public surface (Next, NextGroup, constructors, IncludeX,
LengthRequired) is unchanged and continues to work, except for the
error-handling breaking change above. See docs/migration-v2-to-v3.md.
One column per quarter.
A major release focused on cryptographic correctness, a modern API, and broader use cases. See the v2 → v3 migration guide.
ArgumentException from Next() instead of returning an error
message as the "password". Use TryNext(out var password) for a non-throwing path.net8.0 and net10.0; netstandard2.0
has been dropped. Consumers on .NET Framework or other older runtimes should stay on the 2.x line.CryptoRandomSource) with unbiased integer sampling
(via RandomNumberGenerator.GetInt32 — removes modulo bias).NextAsync, GenerateAsync.AddPasswordGenerator(...) with code and appSettings.json binding
(resolution order: code-configure > appSettings > default).ForOwasp, ForNist, ForOtp, ForApiKey, ForEnvironmentName, ForPassphrase.ForPassphraseWithEntropy(targetBits) derives the word count
to meet a target, and ForPassphrase(..., minimumEntropyBits) enforces an entropy floor.ForPassphrase(..., includeSymbol: true) attaches a random symbol to one
randomly chosen word, so passphrases satisfy "needs a number and a symbol" rules while staying
memorable. Entropy estimation now accounts for both the trailing number and the symbol.char? — pass separator: null (or an
empty string when binding from configuration) to concatenate words with no separator. This does not
affect entropy.ForMemorable() preset: capitalized words sized to at least 80 bits of entropy.PasswordOptions.Passphrase (a PassphraseOptions)
in code or bind a Passphrase section from configuration to resolve a passphrase
IPasswordGenerator.EstimateEntropyBits() is now part of the IPasswordGenerator interface.WithCharacters(string), WithAllAscii().ExcludeAmbiguous(), RequireAtLeast(CharacterClass, count).IEntropyEstimator / PoolEntropyEstimator and EstimateEntropyBits().Generate(count) and a parameterless Generate() driven by
PasswordOptions.DefaultBatchCount.net8.0 and net10.0; nullable reference types enabled..nuspec).PackageIcon + PackageReadmeFile (clears NU5048), SourceLink, deterministic build, and a
.snupkg symbol package.Next, NextGroup, constructors, IncludeX, LengthRequired) is unchanged and
continues to work, aside from the error-handling breaking change noted above.3.0.0 is a major release: cryptographically secure RNG with unbiased sampling, exception/TryNext error handling, async APIs, dependency-injection supp
3.0.0 is a major release: cryptographically secure RNG with unbiased sampling, exception/TryNext error handling, async APIs, dependency-injection support, presets (OWASP/NIST/OTP/API key/passphrase), custom pools, exclude-ambiguous, per-class minimums and entropy estimation. See the migration guide for upgrading from 2.x.
3.0.0 is a major release: cryptographically secure RNG with unbiased sampling, exception/TryNext error handling, async APIs, dependency-injection supp
3.0.0 is a major release: cryptographically secure RNG with unbiased sampling, exception/TryNext error handling, async APIs, dependency-injection support, presets (OWASP/NIST/OTP/API key/passphrase), custom pools, exclude-ambiguous, per-class minimums and entropy estimation. See the migration guide for upgrading from 2.x.
A major release focused on cryptographic correctness, a modern API, and broader use cases. See the v2 → v3 migration guide.
RandomNumberGenerator.GetInt32 (removes modulo bias)ForPassphraseWithEntropy(bits) derives word count to meet a target; minimumEntropyBits enforces a floorForPassphrase(..., includeSymbol: true) satisfies "must contain a symbol" policies without sacrificing memorabilityForOwasp, ForNist, ForOtp, ForApiKey, ForPassphrase, ForMemorableNextAsync, GenerateAsyncGenerate(count)AddPasswordGenerator(...) with code and appsettings.json bindingWithCharacters, WithAllAscii, ExcludeAmbiguous, RequireAtLeastEstimateEntropyBits() is now part of the IPasswordGenerator interfaceArgumentException from Next() instead of returning an error message as the password. Use TryNext(out var password) for a non-throwing path.net8.0 and net10.0; netstandard2.0 has been dropped. Consumers on .NET Framework or older runtimes should stay on the 2.x line.Full Changelog: 2.1.0...v3.0.0-beta01
Removed usage of RNG Crypto Provider Compatible with .NET Core, .NET Framework and .NET Standard Added ability to get a group of passwords in one call
Removed usage of RNG Crypto Provider Compatible with .NET Core, .NET Framework and .NET Standard Added ability to get a group of passwords in one call
See the project history in the Git log and the GitHub releases.
Fixed bug with methods that use bool and int parameters for the Password class
Removed usage of Random and replace it with a method which uses RngCrytopServiceProvider
Changed how it validates special characters to accommodate custom special characters Added ability to change the special characters Changed minimum le
Changed how it validates special characters to accommodate custom special characters Added ability to change the special characters Changed minimum length to 4 and maximum length to 256 for One Time Passcode number support Compatible with .NET Core, .NET Framework and .NET Standard Added ability to get a group of passwords in one call
Added ability to change the special characters Changed minimum length to 4 and maximum length to 256 for One Time Passcode number support Compatible w
Added ability to change the special characters Changed minimum length to 4 and maximum length to 256 for One Time Passcode number support Compatible with .NET Core, .NET Framework and .NET Standard Added ability to get a group of passwords in one call
Compatible with .NET Core, .NET Framework and .NET Standard Added ability to get a group of passwords in one call
Compatible with .NET Core, .NET Framework and .NET Standard Added ability to get a group of passwords in one call
Compatible with .NET Core, .NET Framework and .NET Standard Added ability to get a group of passwords in one call
Compatible with .NET Core, .NET Framework and .NET Standard Added ability to get a group of passwords in one call
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →