Password Generator
Create strong random passwords or passphrases in your browser. Nothing is sent or saved.
Your password
- Strength
- Very strong
- Entropy
- 104 bits
- Time to try every combination
- Over a billion years
Estimate for an offline attack at 10 billion guesses per second against a fast hash. Real attacks can be slower or faster; reused or leaked passwords fall instantly.
More options
Passwords are generated in your browser. They are never sent anywhere and never saved, not even in this browser.
How to use
- Choose Password for a random string of characters, or Passphrase for a series of random words.
- For a password, set the length with the slider or the number box and check the character types the site accepts.
- Pick how many to make at once: 1, 5 or 10.
- Click Copy next to the one you want and paste it into the sign-up form or your password manager.
- Click Generate again for a fresh set. Changing any setting also creates a new set.
Generated in your browser, never sent or stored
This random password generator runs entirely on your device. The page arrives with no password in it; the first one is created only after the tool starts running in your browser. Each character is chosen with crypto.getRandomValues, the browser’s cryptographic random number generator, not Math.random. The tool keeps the results only in the page’s memory: they are not uploaded, logged, saved to local storage or put in the address bar. Reload or close the tab and they disappear.
How each character is picked
Turning a random number into “one of 90 characters” sounds simple, but the common shortcut of taking the remainder after dividing by 90 makes some characters slightly more likely than others. This tool uses rejection sampling instead: random numbers that would cause that bias are thrown away and drawn again, so every character in the pool has exactly the same chance.
When “Use at least one of each selected type” is on, the generator first draws one character from each type you checked (for example one uppercase letter, one digit and one symbol), fills the rest of the length from the whole pool, and then shuffles all positions with a Fisher–Yates shuffle. That way the required characters are not always at the start, which is a pattern attackers know to try first.
Entropy, explained simply
Entropy measures how many possibilities an attacker would have to try. For a password it is length × log2(pool size). With all four types checked the pool is 90 characters, so each character adds about 6.5 bits, and the default 16-character password has about 104 bits. For a passphrase it is words × log2(list size): this tool’s list has 976 words, so each word adds about 9.9 bits and five words give about 50 bits. Adding a number to a passphrase adds a few more bits.
The strength label follows the bits: under 40 is weak, 40–59 fair, 60–79 strong and 80 or more very strong. The time shown is how long it would take to try every combination at 10 billion guesses per second, a fast offline attack against a stolen password database. On average an attacker finds it in half that time. These numbers only hold for passwords that were generated randomly, like the ones here. A password you invented, such as a name plus a year, is much weaker than its length suggests.
Good habits that matter more than any generator
- One password per site. Passwords leaked from one site are routinely tried on others. A unique random password stops that completely.
- Use a password manager. Nobody can remember dozens of random passwords. A manager stores them encrypted and fills them in, so you only need to remember one strong master passphrase.
- Use a passphrase where you must type it. For the master password or your computer login, seven or more random words (about 70 bits) are much easier to type than 16 random characters and still far out of reach of brute force.
- Turn on two-factor authentication (2FA). An authenticator app or a security key protects the account even if a password leaks.
Need to pick names or numbers fairly instead? The random picker uses the same unbiased method. To check how long a piece of text is before you paste it somewhere with a limit, try the word counter.
Frequently asked questions
Is this password generator safe to use?
Passwords are created by JavaScript running in your own browser, using crypto.getRandomValues, the same cryptographic random source browsers use for encryption keys. Nothing is sent to a server and nothing is stored: no cookies, no local storage, no history. Close the tab and the passwords are gone.
How long should my password be?
For a random password with uppercase and lowercase letters, numbers and symbols, 16 characters gives about 104 bits of entropy, far beyond what any offline attack can search. Use 12 as a bare minimum for low-value accounts and 20 or more for a password manager's master password if you're comfortable typing it.
What does entropy in bits mean?
It expresses, as a power of two, how many guesses it could take to find a random secret. Each extra bit doubles the work. A password of 16 characters drawn from 90 possible characters has 16 × log2(90) ≈ 104 bits, meaning about 2^104 possible passwords.
Is a passphrase better than a password?
A passphrase is easier to type and remember, which makes it a good choice for a master password or a computer login. It needs more length to match a random password, though: each word from this tool's 976-word list adds about 10 bits, so use 7 or more words when it really matters.
Why exclude look-alike characters?
Capital I, lowercase l, the digit 1, capital O and zero are easy to misread when you copy a password by hand from paper or another screen. Excluding them makes the pool slightly smaller, and the entropy shown drops to match.
What if a site does not accept some symbols?
Type the symbols the site allows into Custom symbols, for example !@#$, and only those will be used. If a site accepts no symbols at all, uncheck Symbols and make the password a few characters longer instead.
Is the crack time accurate?
It is a rough upper bound for brute force, assuming the attacker has the password's hash and tries 10 billion guesses per second. A slow hash such as bcrypt makes attacks far slower; a password that has leaked or that you reuse can be tried first and cracked at once, whatever its length.
Related tools
- Random PickerDraw random numbers, pick winners from a list of names or split people into fair teams.
- Word CounterCount words, characters, sentences and paragraphs as you type, and see the reading time.
- Typing Speed TestType random common words against the clock and see your words per minute and accuracy.
- Keyboard TesterPress each key and watch it light up on the on-screen keyboard to find dead or stuck keys.