Password Generator
Generate strong, random passwords with custom length and character rules.
Password
—
Strength
—
About this tool
Generates random passwords in your browser using crypto.getRandomValues — the same cryptographically secure random source used for encryption keys, not the predictable Math.random. Choose a length and which character sets to include, and generate as many as you want. Nothing is sent over the network, saved, or logged; refreshing the page discards the result.
Length beats complexity. The strength of a random password is its entropy — roughly, how many equally likely passwords an attacker would have to try. Each character adds a fixed number of bits depending on the alphabet size: about 5.7 bits per character with lowercase + uppercase + digits (62 options), or about 6.6 bits if you add symbols (95 options). Entropy is length × bits-per-character, so adding characters raises it far faster than adding one more symbol type. A 20-character lowercase-and-digit password is stronger than a 10-character one that uses every symbol.
Rough targets. Below about 50 bits is weak against a determined offline attack. 70–80 bits is a reasonable floor for an important account. 100+ bits is comfortably beyond any foreseeable brute force. At ~5.7 bits/character that's roughly 9, 13, and 18 characters respectively.
When a passphrase is better. If you have to type or remember the password, several random words (a passphrase) reach the same entropy as a shorter random string while being far easier to handle. Use a random-string password like this for anything a password manager will store and fill for you.
Don't reuse it. The biggest real-world risk isn't brute force — it's a breach at one site exposing a password you also used elsewhere. A unique password per account, kept in a password manager, matters more than squeezing out extra entropy.
To score a password you already have, use the password strength checker. For codes and one-time values, the UUID generator and random number generator use the same secure source.
Frequently asked questions
- Are these passwords stored or sent anywhere?
- No. Generation happens entirely in your browser. Nothing is transmitted, saved, or logged, and closing or refreshing the page discards the password.
- What makes a password "strong"?
- Mostly its length combined with the size of the character set it's drawn from — together these set its entropy. A longer password with fewer character types often beats a short one packed with symbols.
- Is the randomness actually secure?
- Yes. It uses
crypto.getRandomValues, the browser's cryptographically secure random number generator, notMath.random. Characters are chosen without modulo bias. - Why is at least one character set required?
- With every set unchecked there are no characters to draw from, so the tool asks you to pick at least one.
- Should I use symbols?
- They help a little by enlarging the alphabet, but some sites reject certain symbols and they make a password harder to type. Adding length is the more reliable way to increase strength.
- Is a generated password or a passphrase better?
- For something a password manager stores and autofills, a long random string like this is ideal. For something you must type or memorise, a multi-word passphrase reaches similar strength with less friction.