Htpasswd Generator
Creates .htpasswd lines with bcrypt, APR1-MD5, or SHA-1 hashes for Basic Auth.
Generate strong random passwords with the length and characters you choose. Each one is created with your browser's secure random generator and shows its strength in bits.
Each character is picked with crypto.getRandomValues, the cryptographically secure generator built into your browser. Math.random is never used.
I l 1 | O 0 o removed: 87 characters, about 103 bits. Still strong and easier to read aloud.| Entropy | Rating | Typical use |
|---|---|---|
| Under 50 bits | Weak | Not recommended |
| 50-79 bits | Fair | Low-value accounts with rate limiting |
| 80-127 bits | Strong | Personal and work accounts |
| 128 bits and up | Very strong | Encryption keys, API secrets, admin accounts |
No. They are generated in your browser and disappear when you close the page. We never see them.
At least 16 random characters for accounts you care about. Length adds more strength than extra symbols do.
Both can be strong. A random password packs more entropy per character, so it suits a password manager. A passphrase of five or more random words is easier to remember and type.
The 32 ASCII punctuation characters: !"#$%&'()*+,-./:;<=>?@[\]^_`{|}~.
Often used together with the Password Generator.
Creates .htpasswd lines with bcrypt, APR1-MD5, or SHA-1 hashes for Basic Auth.
Computes checksums of text or files and compares them with an expected hash.
Generates random v4 and time-ordered v7 UUIDs.