About this secure password generator
A strong password is long, random and used for only one account. This generator creates passwords using your browser’s cryptographically secure random number generator, lets you choose the length and which character types to include, and shows an estimate of how strong the result is.
Passwords are created on your device. They are not sent to our servers, logged or stored.
How to use it
- Choose a length with the slider. Longer is stronger; 16–24 characters is a good range for most accounts.
- Tick the character types you want: lower case, upper case, numbers and symbols.
- Tick “Avoid look-alikes” if you will need to read or type the password by hand.
- Copy the password and save it in a password manager. Use “Generate new” for another.
How random is “random”?
Ordinary random functions in programming languages are designed for speed and are predictable if an attacker knows the internal state. Passwords need a cryptographically secure source. This tool uses the Web Crypto API (crypto.getRandomValues), the same kind of randomness browsers use for encryption keys. It also avoids a subtle bias: picking a character with a simple remainder can make some characters slightly more likely than others, so values that would cause bias are discarded and redrawn. The generator guarantees at least one character from each type you chose and then shuffles the result.
Because each character is drawn independently and uniformly, the strength depends only on the length and the size of the character set.
What “bits of entropy” means
Entropy measures how many equally likely passwords an attacker would have to try. Each bit doubles the possibilities. For a random password, entropy equals length multiplied by log2 of the character-set size. A 20-character password using lower case, upper case, digits and symbols has roughly 130 bits of entropy, which is beyond any realistic guessing attack. A 10-digit number has only about 33 bits, which can be cracked quickly.
The strength meter shows this estimate. It assumes the password was generated randomly, as it is here. A password you invent yourself, even a long one built from words and substitutions like “P@ssw0rd!”, is far weaker than its length suggests because attackers try common patterns first.
Good password habits
Use a different password for every account, so that a breach at one site cannot unlock others. A reputable password manager makes this practical: it generates, stores and fills passwords so you only remember one strong master passphrase. Turn on two-factor authentication wherever it is offered, preferably with an authenticator app or a hardware key rather than SMS.
Current guidance, including recommendations from standards bodies such as NIST, favours length and screening against known breached passwords over complicated composition rules and forced periodic changes. Change a password when you have reason to think it was exposed, not on a fixed schedule. Never share passwords by email or chat, and be wary of any site that asks you to “verify” a password.
Frequently asked questions
Are the generated passwords stored or sent anywhere?
No. They are generated in your browser and disappear when you leave or refresh the page.
How long should my password be?
For important accounts, 16 characters or more of random characters is a solid choice, and 20+ is better. Use the longest length the site accepts for a password you will store in a manager.
Do I need symbols?
Not necessarily. Length matters more. Adding symbols enlarges the character set, but some sites reject certain symbols; if so, untick symbols and increase the length.
What does “avoid look-alikes” do?
It removes characters that are easy to confuse when read, such as O and 0, or l, I and 1, which helps if you need to type the password by hand.
Is a passphrase better than a random password?
A passphrase of several randomly chosen words can be strong and easier to type. This tool generates random character strings, which are best stored in a password manager.
Is it safe to use a website to generate passwords?
This tool runs locally in your browser and makes no network requests with your password. As with any online tool, avoid it on a device or browser you do not trust.
Related tools
- JWT DecoderDecode a JSON Web Token locally to read its header, payload and expiry without sending it anywhere.
- Base64 Encoder & DecoderEncode text to Base64 or decode Base64 back to text, with full Unicode and URL-safe support.
- Word & Character CounterCount words, characters, sentences and paragraphs, estimate reading time and see top keywords.
- URL Encoder & DecoderPercent-encode or decode URLs and query strings, and break a URL into its parts.