Password Generator

Generate strong, random passwords with custom length and character rules.

Password

—

Strength

—

About this tool

Generates random passwords in your browser using crypto.getRandomValues — the same cryptographically secure random source used for encryption keys, not the predictable Math.random. Choose a length and which character sets to include, and generate as many as you want. Nothing is sent over the network, saved, or logged; refreshing the page discards the result.

Length beats complexity. The strength of a random password is its entropy — roughly, how many equally likely passwords an attacker would have to try. Each character adds a fixed number of bits depending on the alphabet size: about 5.7 bits per character with lowercase + uppercase + digits (62 options), or about 6.6 bits if you add symbols (95 options). Entropy is length × bits-per-character, so adding characters raises it far faster than adding one more symbol type. A 20-character lowercase-and-digit password is stronger than a 10-character one that uses every symbol.

Rough targets. Below about 50 bits is weak against a determined offline attack. 70–80 bits is a reasonable floor for an important account. 100+ bits is comfortably beyond any foreseeable brute force. At ~5.7 bits/character that's roughly 9, 13, and 18 characters respectively.

When a passphrase is better. If you have to type or remember the password, several random words (a passphrase) reach the same entropy as a shorter random string while being far easier to handle. Use a random-string password like this for anything a password manager will store and fill for you.

Don't reuse it. The biggest real-world risk isn't brute force — it's a breach at one site exposing a password you also used elsewhere. A unique password per account, kept in a password manager, matters more than squeezing out extra entropy.

To score a password you already have, use the password strength checker. For codes and one-time values, the UUID generator and random number generator use the same secure source.

Frequently asked questions

Are these passwords stored or sent anywhere?
No. Generation happens entirely in your browser. Nothing is transmitted, saved, or logged, and closing or refreshing the page discards the password.
What makes a password "strong"?
Mostly its length combined with the size of the character set it's drawn from — together these set its entropy. A longer password with fewer character types often beats a short one packed with symbols.
Is the randomness actually secure?
Yes. It uses crypto.getRandomValues, the browser's cryptographically secure random number generator, not Math.random. Characters are chosen without modulo bias.
Why is at least one character set required?
With every set unchecked there are no characters to draw from, so the tool asks you to pick at least one.
Should I use symbols?
They help a little by enlarging the alphabet, but some sites reject certain symbols and they make a password harder to type. Adding length is the more reliable way to increase strength.
Is a generated password or a passphrase better?
For something a password manager stores and autofills, a long random string like this is ideal. For something you must type or memorise, a multi-word passphrase reaches similar strength with less friction.