Password Generator
Generate random passwords using the browser's cryptographic random number generator, with the entropy shown in bits.
Password Generator
Create strong, secure passwords instantly.
Generated in your browser with the Web Crypto API (crypto.getRandomValues), using rejection sampling so every character is equally likely.
What Password Generator does
People are poor sources of randomness. Passwords invented by hand cluster around words, dates and keyboard patterns, which is precisely what cracking tools try first.
This generator draws from the Web Crypto API's cryptographically secure random number generator, the same source used for key material, and samples the character set without bias. It also reports the entropy of what it produced, so the strength claim is a number you can check rather than a coloured bar.
- Cryptographically secure randomness from the browser's own generator
- Length from 4 to 64 characters
- Toggle uppercase, lowercase, digits and symbols
- Entropy shown in bits, calculated from length and character set size
- One-click copy
How to use Password Generator
- 1
Set the length
Length contributes more to strength than any other setting. Sixteen characters is a sensible floor for an account that matters.
- 2
Choose the character sets
Keep all four enabled unless a site rejects symbols. Removing a set shrinks the pool and lowers entropy.
- 3
Check the entropy figure
Entropy in bits tells you how many guesses an attacker would need on average. Each additional bit doubles that number.
- 4
Copy it into your password manager
Save it before you navigate away. Nothing is stored here, so once the page is gone the password is gone with it.
Example
How entropy scales with length
Input
Character set: upper + lower + digits + symbols (about 92 characters)Output
8 characters ≈ 52 bits
12 characters ≈ 78 bits
16 characters ≈ 104 bits
20 characters ≈ 130 bitsEach extra character adds about 6.5 bits with this character set, which multiplies the search space by roughly 92 times.
When to use it
A new account you will never type by hand
Generate the longest password the site accepts and store it in a password manager.
Service credentials
Database users, API secrets and service accounts benefit most, since nobody has to remember them.
Replacing a reused password
Reuse is the single largest practical risk. A unique generated password per site contains the damage from any one breach.
Limits and known behaviour
- The password is not saved anywhere. If you close the tab without copying it, it cannot be recovered.
- Generated passwords are not memorable by design. They assume a password manager.
- Some sites silently truncate long passwords or reject certain symbols, which can leave you unable to log in with what you saved. Test immediately after changing.
- Entropy measures the generator's output, not your handling of it. A strong password stored in a plain text file is not protected.
- This tool does not check whether a password has appeared in a breach corpus.
Privacy and data handling
Runs entirely in your browser
- Passwords are produced in the page by your browser's cryptographic random number generator. No password is transmitted, and this site never sees one.
- Nothing is stored: no history, no local storage, no cookies. Reloading the page produces a new password and discards the old one.
- Your operating system's clipboard history may retain a copied password. Clear it if that is a concern on a shared machine.
Site-wide data handling, including analytics and advertising, is described in the privacy policy.
Frequently asked questions
Is this actually random?
It uses crypto.getRandomValues, the browser's cryptographically secure generator, and samples characters with rejection sampling so no character is more likely than another. That is the same class of randomness used to generate encryption keys.
Which matters more, length or symbols?
Length. Adding a symbol to an eight-character password helps far less than making it twelve characters. Entropy grows linearly with length and only logarithmically with the size of the character set.
Are 100 bits of entropy enough?
For any realistic offline attack, yes, by an enormous margin. The practical risks to a strong password are phishing, reuse, malware on the device and a breach at the service, none of which more entropy addresses.
Should I change my passwords regularly?
Current guidance from NIST is no: forced rotation pushes people towards predictable variations. Change a password when there is a reason to, such as a breach notification or a shared device.