9
This is what I use:
import base64
import uuid
base64.urlsafe_b64encode(uuid.uuid4().bytes)
I generate a uuid, but I use the bytes instead of larger hex version or one with dashes. Then I encode it into a URL-safe base-64 string. This is a shorter length string than using hex, but using base64 makes it so that the characters in the string are safe for files, urls and most other things.
One problem is that even with the urlsafe_b64encode, it always wants to '='s signs onto the end which are not so url-safe. The '='s signs are for decoding the base-64 encoded information, so if you are only trying to generate random strings, then you can probably safey remove them with:
str.replace('=', '')