Password generator
Strong random passwords made on your device with the browser's cryptographic randomness. Set the length, pick the character sets, click to copy.
Guide
How to use it
- Drag the length slider. 16 characters is a sensible default, longer for anything important.
- Keep all four character sets on unless a site forbids symbols. Tick Exclude look-alikes if you will ever type it from paper.
- Check the meter: aim for 80 bits or more.
- Click a password to copy it, then store it in a password manager.
- Need something you can say out loud? Try the passphrase generator.
Examples
Worked examples
16 characters, all sets on: about 104 bits. Something like t7#Kp2!vXq9-Rm4z, which no rig on earth guesses in a human lifetime.
Symbols off drops each character from 6.7 to 5.95 bits. Compensate with length: 20 characters of letters and digits beats 16 with symbols.
Tick Exclude look-alikes so O and 0, l and 1 never get confused in dictation. Slightly fewer bits per character, so add two characters of length.
Method
How it works
Characters are drawn with crypto.getRandomValues, the browser's cryptographically secure generator, with rejection sampling so every character in the pool is equally likely. Each generated password is checked to contain every set you selected. Entropy is length times log2 of the pool size, and the crack estimate assumes ten billion offline guesses per second.
Everything happens on your device. This site is run by Wolds Cyber, a UK cyber security company, and the generator is built the way we would want to find it built: no server, no storage, no telemetry on what you generate.
FAQ
Frequently asked questions
Is it safe to generate a password on a website?
It is when the generation happens in your browser, as it does here. The passwords are made on your device with the Web Crypto API and never travel over the network. You can load this page, go offline and it still works.
How are the passwords generated?
With crypto.getRandomValues, the browser's cryptographically secure random number generator, using rejection sampling so every character is picked with equal probability. No Math.random anywhere.
How long should a password be?
16 characters with mixed character sets is strong for almost everything. Go longer for password manager master passwords and anything guarding money or email.
What do the bits mean?
Entropy measures how many guesses an attacker needs. Each bit doubles the work. 60 bits is fair, 80 is strong and 100+ is effectively unguessable with current hardware.
How accurate is the crack time?
It assumes an offline attacker making ten billion guesses per second, a realistic figure for a modern GPU rig against a fast hash. Real times vary hugely with how the site stores passwords, so treat it as a comparison tool.
Should I use a password manager?
Yes. A manager remembers a unique random password for every account, which beats any memorable scheme. Use this generator for the odd password that lives outside it, like the manager's own master password or a WiFi key.
Do you store the passwords you generate?
No. They exist only on your screen and in your clipboard when you copy one. There is no server component, no logging and no analytics on what you generate.
More tools