Password Generator
Generate strong random passwords and passphrases in your browser. Cryptographically secure, never transmitted, never stored, never logged.
Related tools
All Security tools →This tool runs entirely in your browser. Nothing you enter is sent to our servers, so there is nothing for us to store or see.
About the Password Generator
Generate passwords that are genuinely random, using the Web Crypto API — your browser cryptographically secure random source, the same one used for TLS. Many online generators use Math.random, which is predictable enough that an attacker who knows the generator can narrow the search space dramatically.
The strength estimate shown is entropy in bits, calculated from the character set and length rather than the "must contain a symbol" heuristics that most strength meters use. Entropy is the honest measure: it tells you how many guesses an attacker needs, and it is why a long passphrase of ordinary words beats a short string of punctuation.
Everything is generated on your device and nothing is transmitted. That is the only acceptable design for this tool — a password generator that sends its output anywhere, even over HTTPS, has defeated its own purpose.
How to use the Password Generator
-
Choose a type
Random characters for maximum strength per character, or a passphrase of real words when you need something you can type or remember.
-
Set the length
Sixteen characters or four words is a sensible floor. The entropy figure updates as you adjust, so you can see what the change actually buys.
-
Adjust the character set
Include or exclude symbols and digits to satisfy a site rules. You can also exclude look-alike characters such as l, 1, I, O and 0.
-
Copy it straight into your password manager
Use Copy and paste it directly where it is needed. Nothing here is stored, so once you leave the page it is gone.
Frequently asked questions
Are these passwords actually random?
Yes. They use crypto.getRandomValues, your browser cryptographically secure random number generator, with rejection sampling to avoid the modulo bias that would otherwise make some characters slightly more likely than others. Math.random is never used.
Is the password sent to your server?
No, and it never could be — generation happens entirely in your browser and there is no network request involved. You can verify this by opening your browser network tab, or by disconnecting from the internet after the page loads and generating one anyway.
What length should I choose?
Sixteen random characters gives roughly 95 bits of entropy, which is beyond brute force for the foreseeable future. Twenty or more is sensible for anything protecting other credentials, such as a password manager master password or an email account.
Is a passphrase weaker than random characters?
Not necessarily. A four-word passphrase from a large word list gives around 52 bits, and six words gives about 78 — comparable to a twelve-character random password but far easier to type on a phone or read aloud. Length compensates for the smaller per-unit entropy.
Should I reuse a generated password anywhere?
No. Use a unique password for every account and store them in a password manager. The single biggest cause of account compromise is credential stuffing, where a password leaked from one breached site is tried against every other service you use.