Password Generator
Strong random passwords with the rules you pick. Free, private and done entirely in your browser — nothing is uploaded.
…Strong random password generator
Passwords are generated with your browser’s cryptographic random number generator (crypto.getRandomValues) and never leave your device. Nothing is logged.
What makes a password strong?
- Length beats complexity. A 16-character password with letters and numbers is far harder to crack than an 8-character one full of symbols.
- Uniqueness. Never reuse a password across sites — one breach exposes them all.
- Randomness. Words, dates and keyboard patterns are the first thing attackers try.
Where should I keep it?
Use a password manager. It remembers the random passwords for you and fills them in automatically, so you only need to remember one master password.
What does a password generator do?

A password generator creates random passwords that people can’t guess and cracking software can’t feasibly work through. This one lets you choose a length from 6 to 64 characters, pick any mix of uppercase letters, lowercase letters, numbers and symbols, and optionally skip look-alike characters. It shows a strength rating in bits of entropy and can produce five passwords at once.
Every password contains at least one character from each set you tick, so it passes “must include a number and a symbol” rules, and the characters are then shuffled so those guaranteed ones don’t always sit at the start.
Password entropy explained simply
Entropy measures how hard a password is to guess, in bits. Each extra bit doubles the number of possibilities an attacker has to try. For a randomly generated password the formula is: entropy = length × log2(number of possible characters).
Take the default settings: 16 characters with all four sets ticked. The pool is 26 uppercase + 26 lowercase + 10 digits + 24 symbols = 86 characters. log2(86) is about 6.43 bits per character, and 16 × 6.43 ≈ 102.8 bits, so the meter shows about 103 bits, rated Very strong. That is 8616, roughly 9.0 × 1030 possible passwords.
The meter labels results under 40 bits as Weak, 40–59 as Fair, 60–89 as Strong and 90 or more as Very strong. Ticking Avoid look-alikes removes I, O, l, o, 0 and 1, leaving 80 characters; a 16-character password then has about 101.2 bits instead of 102.8, a tiny cost that is worth it if you ever have to type the password by hand. The meter estimates strength from the types of characters present, so it doesn’t subtract for this.
Length vs character set
| Characters used | Pool | Length | Possible passwords | Entropy | Average time at 1 trillion guesses per second |
|---|---|---|---|---|---|
| Digits only | 10 | 8 | 100 million | 26.6 bits | Instant |
| Lowercase | 26 | 8 | 2.1 × 1011 | 37.6 bits | About 0.1 seconds |
| All four sets | 86 | 8 | 3.0 × 1015 | 51.4 bits | About 25 minutes |
| Lowercase and digits | 36 | 12 | 4.7 × 1018 | 62.0 bits | About 27 days |
| Upper, lower and digits | 62 | 12 | 3.2 × 1021 | 71.5 bits | About 51 years |
| Lowercase | 26 | 16 | 4.4 × 1022 | 75.2 bits | About 690 years |
| All four sets | 86 | 12 | 1.6 × 1023 | 77.1 bits | About 2,600 years |
| All four sets | 86 | 16 | 9.0 × 1030 | 102.8 bits | About 140 billion years |
The times assume a truly random password and a hypothetical offline attacker making one trillion guesses per second, who on average finds it after trying half the possibilities. Real speeds vary hugely depending on how a website stored the password, and live login pages usually block rapid guessing, so use the figures for comparison only. The lesson is clear: a 16-character lowercase password beats an 8-character one that uses every symbol, because length adds strength faster than complexity does.
Password advice that actually helps
- Use a different password for every account. Attackers routinely try passwords leaked from one site on others.
- Go long for important accounts. 16 characters or more for email, banking and your password manager.
- Turn on two-factor authentication or passkeys wherever they are offered, especially for email, since it can reset everything else.
- Change passwords when there’s a reason, such as a breach notice or a suspicious login, rather than on a fixed schedule. NIST’s guidance (SP 800-63B) tells services not to force routine changes without evidence of compromise.
- If a site rejects symbols, untick them and add a few extra characters of length to keep the entropy up.
- Don’t send passwords in chats or emails, or leave them in plain notes apps.
More questions
Is it safe to use an online password generator?
It depends on how it works. This password generator creates passwords on your own device and sends nothing over the internet. For extra safety, generate passwords on a device you trust and save them straight into your password manager.
How long should a password be?
NIST’s current guidance for services asks for at least 15 characters when a password is the only login factor and at least 8 when it is combined with another factor, and says sites should accept passwords of at least 64 characters. For a random password, 16 characters or more is a sensible personal minimum.
Is a passphrase better than a random password?
A passphrase of several randomly chosen words is easier to remember and type. Five words picked at random from a 7,776-word list give about 64.6 bits of entropy, while a 16-character random password gives about 103 bits. Use a passphrase for the few passwords you must memorize, and random passwords stored in a manager for everything else.
Why does a website reject my generated password?
Some sites cap the length or only allow certain symbols. Try unticking !@# or lowering the length to the site’s maximum, then generate again.
Setting up a guest Wi-Fi network? Generate its key here, then share it with a QR Code Generator Wi-Fi code. You may also find the Word Counter and Token Counter useful.
Further reading: NIST SP 800-63B Digital Identity Guidelines.