Password Generator
Offer a strong password in one click wherever someone sets or changes credentials.
What it adds
A generate control on password fields that produces a strong value, shows it, and hands it to the user safely.
What your agent is told to do
5
What your agent is told to do
5-
1
Add the control to every place a password is set: sign-up, password change, password reset completion, and any admin screen that provisions credentials for someone else.
-
2
Generate the value in the browser using the platform's cryptographic random source. The value must never be produced on the server or sent anywhere.
-
3
Reveal the generated password by default so the user can record it, and offer a regenerate control beside it. A hidden generated password that the user cannot see is a password they will immediately reset.
-
4
Feed the generated value straight into the app's existing Password Strength Meter and validation rather than adding a second, parallel indicator. If the generator produces something the app's own policy rejects, the policy and the generator are out of step and the generator is wrong.
-
5
Do not use the language's ordinary random number helper. It is seeded predictably, and a password generated from it is guessable given enough samples.
Edge cases it handles
8
Edge cases it handles
8- Use a cryptographically secure random source. A general-purpose pseudorandom helper produces sequences an attacker can reproduce, which quietly makes every password it generated weak.
- If the password policy requires an uppercase letter, a digit, or a symbol, the generator must guarantee each required class appears rather than hoping random selection covers them. Place the guaranteed characters at random positions, not at the start.
- Offer a mode that excludes look-alike characters such as capital I, lowercase l, digit one, capital O, and zero, for passwords that will be read aloud or typed from a screen.
- The generated value must never be logged, sent in analytics, included in an error report, or persisted anywhere but the user's own password field. Check that form autofill and error-tracking tooling are not capturing it.
- Do not leave the value on screen or in the clipboard indefinitely. Re-mask it once the form is submitted, and tell the user the clipboard still holds it rather than pretending it was cleared.
- Some password managers replace the field value after the user has generated one. Detect the change and do not overwrite the manager's value with a stale generated string.
- Length matters more than symbol variety. Default to a generous length rather than a short password stuffed with punctuation, and let the user increase it.
- Symbols the target system rejects, or that break when pasted into a terminal or a connection string, must be excludable without regenerating from scratch.
Definition of done
9
Definition of done
9- Every credential-setting screen offers one-click generation.
- Generation uses the platform's cryptographic random source, verified by inspection of the code path.
- Every character class the password policy requires is present in every generated value.
- A look-alike-free mode is available for passwords that will be typed or spoken.
- The generated value never appears in logs, analytics, or error reports.
- The generated value is shown to the user and re-masked after submission, with an honest note about the clipboard.
- Generated passwords always pass the app's own validation and strength meter.
- The feature matches the existing design system.
- No existing functionality is broken.
Related features
Idempotent Form Submission
Idempotent Form Submission
Make one submit mean one result, even when the network retries.
What it does
Idempotency keys on high-impact writes so a double-click, a retry, or a refresh cannot create the same record twice.
How it works
- 1 Find the writes where a duplicate is expensive — payments, orders, invitations, provisioning, anything that sends money or email.
- 2 Generate an idempotency key when the form is rendered, send it with the submission, and persist it server-side alongside the result of the first successful attempt.
- 3 When the same key arrives again, return the stored result instead of doing the work a second time. When the same key arrives with a different payload, reject it — that is a client bug, not a retry.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/idempotent-form-submission
Client Version Compatibility
Client Version Compatibility
Handle the tab that has been open since two deploys ago.
What it does
The server tells the client which build it expects, and the client responds — quietly for an optional update, insistently when the old code can no longer talk to the API.
How it works
- 1 Stamp every build with a version identifier and return it on API responses, either in a header or a small metadata endpoint. The client compares it against the version it was built as.
- 2 Separate two cases and treat them differently. A newer build being available is an optional update — offer it and let the user finish what they are doing. An API contract the running client cannot satisfy is a hard incompatibility and must block further writes.
- 3 For an optional update, show an unobtrusive, dismissible prompt and apply the new version at the next natural navigation. Do not interrupt.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/client-version-compatibility
Backup Verification
Backup Verification
Prove your backups restore, instead of trusting that they exist.
What it does
Automated checks that a backup is complete, encrypted, retained, and actually restorable — with a recorded test restore rather than an assumption.
How it works
- 1 Inventory what must be backed up first: every database, every uploaded-file store, and any external state the app cannot rebuild. A backup covering only the primary database is a partial backup, and should be reported as one.
- 2 After every backup, verify it mechanically: the file exists, its checksum matches, its size is within a sane band of the previous run, it is encrypted, and it is where the retention policy expects it.
- 3 Restore on a schedule into a fully isolated environment and assert against the restored data — row counts within expected ranges, the newest record close to the backup time, and a handful of known invariants.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/backup-verification
How it works
-
1
Copy the link
Grab the Markdown instruction URL for this feature.
-
2
Give it to your AI
Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.
-
3
It inspects, then implements
Your agent reads your existing app first, then adds the feature to fit it.
Works with your stack
These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.
Need it tighter than that? Customize the feature and tell it exactly what you're running.