Password Generator
Strong passwords generated in your browser.
Eight is the floor; sixteen or more is a sensible default.
Something went wrong
Processed locally in your browser. Nothing you type here is sent to our servers.
Where these passwords come from
Every password on this page is generated by your own browser using
crypto.getRandomValues(), the same cryptographically secure source that
underpins TLS key generation. No password is ever sent to a server, written to
storage, or logged. There is no endpoint that could receive one.
Regenerating replaces what is on screen, and leaving the page discards it entirely. If you want to keep a password, put it in a password manager now.
Reading the strength meter
The number that matters is entropy in bits, and it comes from a simple calculation: the size of the character set, raised to the length. Twenty characters drawn from a 94-character alphabet gives about 131 bits.
Bits are exponential. Each additional bit doubles the work required to guess the
password. That is why length beats complexity: adding one character
to a password multiplies the search space by the size of the alphabet, whereas
swapping a for @ adds essentially nothing and makes the
password harder to type.
Roughly: below 40 bits is weak, 60–80 is fine for ordinary accounts, and beyond 100 bits you are far past what any offline attack can reach. These labels are deliberately conservative.
How to use it
- Drag the length slider — longer is genuinely better.
- Choose which character sets to include.
- Exclude look-alike characters if you will ever have to read the password aloud or type it from a screen.
- Copy it straight into your password manager.
Practical advice
- Use a password manager. A generated password you cannot remember is only useful if something else remembers it for you.
- Never reuse one. Reuse is what turns one site's breach into a problem everywhere else, and no amount of entropy protects against it.
- Turn on two-factor authentication wherever it is offered. It protects you even when the password itself leaks.
- Rotating passwords on a schedule is no longer recommended by NIST — rotate when you have a reason to believe one is exposed.
Limitations
- The entropy figure assumes a uniform random draw, which is what this tool does. It does not apply to passwords a human invented — those are far weaker than their length suggests.
- Some sites impose maximum lengths or ban certain symbols. Adjust the options rather than trimming the password by hand.
- A password shown on screen can be read over your shoulder or captured by screen-recording software. Generate on a machine you trust.
- For a passphrase you actually need to memorise, several random words are easier to remember at equivalent strength than a random character string.