random.SystemRandom

Every method of Random (randint, choice, sample, shuffle, gauss …) but fed by the operating system instead of the Mersenne Twister. Its output cannot be predicted or replayed, so this page has no live demo. secrets.SystemRandom is the same class.

random classAll Python 3 versions
Common call
rng = random.SystemRandom(); rng.randint(1, 6)
Returns
the usual Random methods, unpredictable values
Replaces
random.* when values must not be guessable
Watch out
seed() does nothing; getstate()/setstate() raise NotImplementedError
random.SystemRandom(xx — Passed to seed(), which ignores it.type: object · default: None=None)
→ SystemRandom

Parameters

NameTypeRequiredDescription
xobjectno (None)Passed to seed(), which ignores it.

Return value

SystemRandom — A generator backed by os.urandom(); the argument is accepted and ignored.

Attributes

AttributeTypeMeaning
random()methodOverridden: 56 bits from os.urandom(7), shifted to 53 bits, times 2**-53.
getrandbits(k)methodOverridden: (k + 7) // 8 bytes from os.urandom, extra bits shifted off. ValueError for k < 0.
randbytes(n)methodOverridden: os.urandom(n) directly.
seed(*args, **kwds)methodStub: does nothing and returns None.
getstate() / setstate(state)methodRaise NotImplementedError: System entropy source does not have state.

Common patterns

Secure picks with the familiar API
sample, shuffle and choices with an unpredictable source.
import random
secure = random.SystemRandom()
winners = secure.sample(entrants, 3)
secure.shuffle(deck)
Prefer secrets for tokens
The secrets module wraps the same source with purpose-built helpers.
import secrets
token = secrets.token_urlsafe(32)
code = secrets.randbelow(1_000_000)
pick = secrets.choice(['a', 'b', 'c'])
Random password
Uniform characters from the OS source.
import secrets
import string
alphabet = string.ascii_letters + string.digits
password = ''.join(secrets.choice(alphabet) for _ in range(20))

Examples

1. It is a Random subclass
import random isinstance(random.SystemRandom(), random.Random)
Returns
True
2. random() stays in [0, 1)
import random 0 <= random.SystemRandom().random() < 1
Returns
True
3. All Random methods work
import random random.SystemRandom().randint(1, 6) in range(1, 7)
Returns
True
4. randbytes is os.urandom
import random len(random.SystemRandom().randbytes(16))
Returns
16
5. seed() is ignored
import random print(random.SystemRandom().seed(42))
Returns
None
6. No state to save
import random random.SystemRandom().getstate()
Returns
NotImplementedError: System entropy source does not have state.
7. secrets.SystemRandom is this class
import random import secrets secrets.SystemRandom is random.SystemRandom
Returns
True

Pitfalls

1. Seeding it for reproducible tests
seed() is a stub on SystemRandom, so two "identically seeded" instances still disagree. Use random.Random(seed) when you need repeatability.
SystemRandom(42)
import random
a = random.SystemRandom(42)
b = random.SystemRandom(42)
a.getrandbits(128) == b.getrandbits(128)
False
Random(42)
import random
a = random.Random(42)
b = random.Random(42)
a.getrandbits(128) == b.getrandbits(128)
True
2. Calling setstate() on it
There is no software state to restore; both state methods raise.
setstate
import random
random.SystemRandom().setstate(None)
NotImplementedError: System entropy source does not have state.
Random instance
import random
r = random.Random(5)
r.setstate(random.Random(5).getstate())
r.random() == random.Random(5).random()
True

When to use

Use it
  • Security-relevant picks with the Random API: sample, shuffle, choices, uniform
  • Code that already takes a Random instance and must become unpredictable
Reach for something else
  • Tokens, passwords, keys → secrets (clearer intent, same source)
  • Reproducible runs, tests, simulations → random.Random(seed)
  • Generating huge amounts of data quickly: every call is a system call

Notes

CPython impl
Lib/random.py: SystemRandom overrides random(), getrandbits(), randbytes(), seed() (stub) and getstate/setstate (raise NotImplementedError); every other method is inherited from Random and therefore uses these. os.urandom reads getrandom() / /dev/urandom on Linux and BCryptGenRandom on Windows
Availability
The docs say "Not available on all systems" (wherever os.urandom is unavailable)
Why no demo
Values come from the OS and are different on every call; the examples check only properties that always hold

FAQ

It draws from os.urandom(), the operating system source recommended for cryptographic use, and it is what the secrets module uses internally. For tokens and passwords call the secrets functions, which make the intent explicit.