# ACL GENPASS

> Generate a cryptographically strong random password.

Use `ACL GENPASS` to generate a random, hex-encoded password suitable for a new ACL user.

The optional `bits` argument controls the strength of the generated password, rounded up to the nearest multiple of 8, and defaults to 256 bits when omitted. This only generates the password string; it does not create or update a user. To actually authenticate an ACL user over the REST API, generate credentials with [`ACL GENTOKEN`](/redis/commands/server/acl-gentoken) instead, since a plain password from `GENPASS` cannot be passed to [`ACL SETUSER`](/redis/commands/server/acl-setuser).

## Syntax

```redis
ACL GENPASS [bits]
```

## Arguments

| Argument | Required | Repeatable | Description |
| --- | --- | --- | --- |
| `bits` | No | No | Password strength in bits, from 1 to 4096. Defaults to 256 and is rounded up to a multiple of 8. |

## Important points

- The returned password is not stored anywhere; it is only generated and returned.
- This value cannot be added to a user with `ACL SETUSER ... >password`. Use [`ACL GENTOKEN`](/redis/commands/server/acl-gentoken) to create credentials that `SETUSER` will accept.

## Response

The reply reports the result of the operation. Error replies have the same shape in RESP2 and RESP3 and are surfaced as exceptions by the SDKs below.

| Protocol | Reply |
| --- | --- |
| RESP2 | Bulk string |
| RESP3 | Bulk string |

<Note>
  Client libraries often decode bulk strings, maps, sets, and numeric strings into language-native values. The table describes the Redis wire reply.
</Note>

## Examples

TCP examples use the TLS `REDIS_URL` from the Upstash console. REST examples use `UPSTASH_REDIS_REST_URL` and `UPSTASH_REDIS_REST_TOKEN`.

<AccordionGroup>

<Accordion title="Redis CLI" icon="terminal">

```bash
ACL GENPASS
```

</Accordion>

<Accordion title="@upstash/redis" icon="node-js" iconType="brands">

<Note>
  This command is not supported yet in `@upstash/redis`.
</Note>

</Accordion>

<Accordion title="upstash_redis" icon="python" iconType="brands">

<Note>
  This command is not supported yet in `upstash_redis`.
</Note>

</Accordion>

<Accordion title="ioredis" icon="node-js" iconType="brands">

```ts
import Redis from "ioredis";

const redis = new Redis(process.env.REDIS_URL!);
const result = await redis.acl("GENPASS");
console.log(result);
```

</Accordion>

<Accordion title="node-redis" icon="node-js" iconType="brands">

```ts
import { createClient } from "redis";

const client = await createClient({ url: process.env.REDIS_URL })
  .on("error", console.error)
  .connect();
const result = await client.aclGenPass();
console.log(result);
```

</Accordion>

<Accordion title="redis-py" icon="python" iconType="brands">

```python
import os
import redis

client = redis.from_url(os.environ["REDIS_URL"])
result = client.acl_genpass()
print(result)
```

</Accordion>

<Accordion title="go-redis" icon="golang" iconType="brands">

```go
package main

import (
    "context"
    "fmt"
    "os"

    "github.com/redis/go-redis/v9"
)

func main() {
    opts, err := redis.ParseURL(os.Getenv("REDIS_URL"))
    if err != nil {
        panic(err)
    }
    client := redis.NewClient(opts)
    result, err := client.ACLGenPass(context.Background(), 0).Result()
    if err != nil {
        panic(err)
    }
    fmt.Println(result)
}
```

</Accordion>

<Accordion title="jedis" icon="java" iconType="brands">

```java
import java.net.URI;

import redis.clients.jedis.Jedis;

try (Jedis jedis = new Jedis(new URI(System.getenv("REDIS_URL")))) {
  Object result = jedis.aclGenPass();
  System.out.println(result);
}
```

</Accordion>

<Accordion title="redis-rs" icon="rust" iconType="brands">

```rust
use redis::TypedCommands;

fn main() -> redis::RedisResult<()> {
    let url = std::env::var("REDIS_URL").expect("REDIS_URL is not set");
    let client = redis::Client::open(url)?;
    let mut connection = client.get_connection()?;

    let result = connection.acl_genpass()?;
    println!("{result:?}");
    Ok(())
}
```

</Accordion>

</AccordionGroup>
