Strong Password Generator

Create strong, truly random passwords with the length and characters you need. They are generated on your device and never sent anywhere.

Password settings

16
Include
Generated on your device with crypto.getRandomValues. Nothing is sent or saved.

Your password

—
Strong —
Character pool
—
Time to guess (offline, 10¹⁰/s)
—
More passwords

    How to use the password generator

    This password generator creates a strong random password as soon as the page opens, and a new one every time you change a setting.

    1. Set the length with the slider or a preset. 16 characters is a solid default for most accounts.
    2. Choose which character types to include: uppercase, lowercase, numbers and symbols. The password always contains at least one character from each type you select, so it passes sites that require "one number and one symbol".
    3. Tick Exclude look-alikes if you may need to read or type the password by hand.
    4. Press Copy and paste it straight into the sign-up form or your password manager. Use Regenerate for a fresh one, or Generate 5 to pick from a short list.

    How the passwords are made

    Each character is picked with crypto.getRandomValues, the cryptographically secure random number generator built into your browser. It is a different thing from Math.random, which is fine for games but predictable enough that it should never be used for passwords.

    Turning a random number into a character fairly takes a little care. A common shortcut is random % 87, but because 232 is not a multiple of 87, the first few characters in the list would come up slightly more often. This tool uses rejection sampling instead: any random value that falls in the incomplete top range is thrown away and a new one is drawn, so every character has exactly the same chance.

    To guarantee each chosen type appears, one character is drawn from each type first, the remaining positions are filled from the full pool, and the result is shuffled with a Fisher–Yates shuffle so the guaranteed characters do not sit in predictable places.

    What the strength meter means

    Strength is measured in bits of entropy, which describes how many possible passwords the generator could have produced with your settings.

    Entropy (bits) = length × log₂(pool size)

    Example: 16 characters drawn from all four types (87 characters) gives 16 × log₂(87) ≈ 16 × 6.44 ≈ 103 bits. Every extra bit doubles the work for an attacker.

    SettingsPoolEntropyMeter
    8 characters, lowercase only26≈ 38 bitsVery weak
    8 characters, all types87≈ 52 bitsWeak
    12 characters, all types87≈ 77 bitsFair
    16 characters, all types87≈ 103 bitsVery strong
    20 characters, letters and numbers62≈ 119 bitsVery strong

    The "time to guess" figure assumes an attacker who has stolen a password database and can test ten billion guesses per second offline, finding the password after searching half the possibilities on average. Real attacks vary a lot with how the site stored passwords, so treat it as a comparison, not a promise. The calculation only applies to randomly generated passwords; a password you invent yourself is usually far weaker than its length suggests.

    Tips for using strong passwords

    This page does not store, log or send the passwords it creates. Once you close or reload it, they are gone.

    Frequently asked questions

    Is this password generator safe to use?

    Yes. Passwords are created in your browser with the Web Crypto API (crypto.getRandomValues), the same secure random source browsers use for encryption. Nothing is sent to a server, logged or stored.

    How long should a password be?

    For accounts protected by a password manager, 16 characters or more with mixed character types is a good default. For a password you must type often, length matters more than symbols: a longer password is harder to guess than a short complex one.

    What does entropy in bits mean?

    Entropy measures how many guesses a random password could take. Each extra bit doubles the number of possibilities. It is calculated as length × log2(number of possible characters), so 16 characters from 87 symbols gives about 103 bits.

    Why exclude look-alike characters?

    Characters like I, l, 1, O and 0 are easy to confuse when you read a password aloud or type it from paper. Excluding them makes the pool slightly smaller, so the tool shows a little less entropy, but the difference is small.

    Should I use the same strong password everywhere?

    No. If one site is breached, attackers try the same email and password on other sites. Use a different password for every account and keep them in a password manager.