English
How to use the password generator
This password generator creates a strong random password as soon as the page opens, and a new one every time you change a setting.
- Set the length with the slider or a preset. 16 characters is a solid default for most accounts.
- Choose which character types to include: uppercase, lowercase, numbers and symbols. The password always contains at least one character from each type you select, so it passes sites that require "one number and one symbol".
- Tick Exclude look-alikes if you may need to read or type the password by hand.
- Press Copy and paste it straight into the sign-up form or your password manager. Use Regenerate for a fresh one, or Generate 5 to pick from a short list.
How the passwords are made
Each character is picked with crypto.getRandomValues, the cryptographically secure random number generator built into your browser. It is a different thing from Math.random, which is fine for games but predictable enough that it should never be used for passwords.
Turning a random number into a character fairly takes a little care. A common shortcut is random % 87, but because 232 is not a multiple of 87, the first few characters in the list would come up slightly more often. This tool uses rejection sampling instead: any random value that falls in the incomplete top range is thrown away and a new one is drawn, so every character has exactly the same chance.
To guarantee each chosen type appears, one character is drawn from each type first, the remaining positions are filled from the full pool, and the result is shuffled with a Fisher–Yates shuffle so the guaranteed characters do not sit in predictable places.
What the strength meter means
Strength is measured in bits of entropy, which describes how many possible passwords the generator could have produced with your settings.
Example: 16 characters drawn from all four types (87 characters) gives 16 × log₂(87) ≈ 16 × 6.44 ≈ 103 bits. Every extra bit doubles the work for an attacker.
| Settings | Pool | Entropy | Meter |
|---|---|---|---|
| 8 characters, lowercase only | 26 | ≈ 38 bits | Very weak |
| 8 characters, all types | 87 | ≈ 52 bits | Weak |
| 12 characters, all types | 87 | ≈ 77 bits | Fair |
| 16 characters, all types | 87 | ≈ 103 bits | Very strong |
| 20 characters, letters and numbers | 62 | ≈ 119 bits | Very strong |
The "time to guess" figure assumes an attacker who has stolen a password database and can test ten billion guesses per second offline, finding the password after searching half the possibilities on average. Real attacks vary a lot with how the site stored passwords, so treat it as a comparison, not a promise. The calculation only applies to randomly generated passwords; a password you invent yourself is usually far weaker than its length suggests.
Tips for using strong passwords
- One password per account. Reused passwords are the main way one data breach spreads to your other accounts.
- Use a password manager so you never need to remember these strings. Most browsers and phones include one.
- Turn on two-factor authentication for email, banking and social accounts. It protects you even if a password leaks.
- Length beats complexity when you must type a password often. If a site rejects some symbols, untick Symbols and add a few characters of length instead.
This page does not store, log or send the passwords it creates. Once you close or reload it, they are gone.
Frequently asked questions
Is this password generator safe to use?
Yes. Passwords are created in your browser with the Web Crypto API (crypto.getRandomValues), the same secure random source browsers use for encryption. Nothing is sent to a server, logged or stored.
How long should a password be?
For accounts protected by a password manager, 16 characters or more with mixed character types is a good default. For a password you must type often, length matters more than symbols: a longer password is harder to guess than a short complex one.
What does entropy in bits mean?
Entropy measures how many guesses a random password could take. Each extra bit doubles the number of possibilities. It is calculated as length × log2(number of possible characters), so 16 characters from 87 symbols gives about 103 bits.
Why exclude look-alike characters?
Characters like I, l, 1, O and 0 are easy to confuse when you read a password aloud or type it from paper. Excluding them makes the pool slightly smaller, so the tool shows a little less entropy, but the difference is small.
Should I use the same strong password everywhere?
No. If one site is breached, attackers try the same email and password on other sites. Use a different password for every account and keep them in a password manager.