Password Generator

Generate strong random passwords with the length and characters you choose. Each one is created with your browser's secure random generator and shows its strength in bits.

Updated
Generated in your browser. Passwords are never sent or stored.
Characters

Passwords
    Uses crypto.getRandomValues.

    How to use the Password Generator

    1. Set the Length. 16 characters or more is a good default for accounts, and 32 or more for API keys and secrets.
    2. Tick the Characters to include, and Avoid look-alikes if the password will be read or typed by hand.
    3. Press Generate, then copy one password or the whole list.

    How it works

    Each character is picked with crypto.getRandomValues, the cryptographically secure generator built into your browser. Math.random is never used.

    • Rejection sampling keeps every character equally likely, with no modulo bias.
    • Every ticked character set appears at least once, so a site that demands a digit or a symbol will accept the result. The positions are then shuffled with a Fisher-Yates shuffle.
    • Strength is the entropy: length × log2(pool size). A 20-character password from all 94 printable characters has 20 × 6.55 ≈ 131 bits.

    Examples

    • 12 characters, lowercase only: 26 possible characters, 12 × 4.70 ≈ 56 bits. Weak against offline cracking.
    • 16 characters, all four sets: 94 characters, about 105 bits. Strong.
    • 16 characters, all sets with the look-alikes I l 1 | O 0 o removed: 87 characters, about 103 bits. Still strong and easier to read aloud.
    • 32 characters, letters and digits only: 62 characters, about 191 bits. Good for API keys that can't contain symbols.

    Password strength by entropy

    EntropyRatingTypical use
    Under 50 bitsWeakNot recommended
    50-79 bitsFairLow-value accounts with rate limiting
    80-127 bitsStrongPersonal and work accounts
    128 bits and upVery strongEncryption keys, API secrets, admin accounts

    Limitations

    • Entropy measures how the password was generated. It doesn't help if the password is reused, shared, or stored in plain text.
    • Some sites limit length or reject certain symbols. Untick Symbols or shorten the password if a site refuses it.
    • Passwords are not saved anywhere. Copy them into a password manager before you leave the page.

    Frequently asked questions

    Are these passwords sent to a server or stored?

    No. They are generated in your browser and disappear when you close the page. We never see them.

    How long should a password be?

    At least 16 random characters for accounts you care about. Length adds more strength than extra symbols do.

    Is a random password better than a passphrase?

    Both can be strong. A random password packs more entropy per character, so it suits a password manager. A passphrase of five or more random words is easier to remember and type.

    Which characters count as symbols?

    The 32 ASCII punctuation characters: !"#$%&'()*+,-./:;<=>?@[\]^_`{|}~.

    Often used together with the Password Generator.

    • Htpasswd Generator

      Creates .htpasswd lines with bcrypt, APR1-MD5, or SHA-1 hashes for Basic Auth.

    • Hash Generator

      Computes checksums of text or files and compares them with an expected hash.