How to use
- Set the length (16 by default) and pick character sets: uppercase, lowercase, digits, symbols. Every set you pick is guaranteed at least one character.
- If you will ever type the password by hand, turn on Exclude look-alikes (I l 1 O 0 o). If a site rejects certain symbols, list them under Also exclude.
- Choose how many (1–20) and the passwords appear instantly. Hit Regenerate for a fresh batch and Copy next to the one you want.
Entropy and strength
Entropy measures how hard a random password is to guess, in bits: length × log₂(pool size). Each extra bit doubles the number of possible passwords.
| Character sets | Pool | 12 chars | 16 chars | 20 chars |
|---|---|---|---|---|
| Digits only | 10 | 39.9 bits | 53.2 bits | 66.4 bits |
| Lowercase only | 26 | 56.4 bits | 75.2 bits | 94.0 bits |
| Upper + lower + digits | 62 | 71.5 bits | 95.3 bits | 119.1 bits |
| All, with 28 symbols | 90 | 77.9 bits | 103.9 bits | 129.8 bits |
The strength label is this tool’s own scale: under 40 bits very weak, under 60 weak, under 80 fair, under 100 strong, 100 and above very strong. These numbers only hold for randomly generated passwords, not ones a person made up.
Why length beats complexity
Adding symbols to a 16-character password (pool 62 → 90) raises entropy from 95.3 to 103.9 bits — 8.6 bits. Keeping letters and digits and adding just two more characters does better (18 chars = 107.2 bits). Forced-symbol rules mostly push people toward patterns like Password1!, which is why NIST’s Digital Identity Guidelines (SP 800-63B) favor adequate length and screening against breached-password lists over composition rules.
Passphrases and password managers
- Passphrases: for the few passwords you must memorize — your computer login, your password manager’s master password — string together several randomly chosen words. Picking from the 7,776-word Diceware list gives about 12.9 bits per word, so six words is roughly 77.5 bits. A sentence you invent yourself is not random and is much weaker.
- Password managers: using a different password on every site matters most, because passwords leaked from one site are routinely tried on others. Nobody can memorize dozens of them, so let a manager store them, and turn on two-factor authentication for important accounts.
- Need random identifiers instead? Try the UUID generator. To hash a string, use the hash generator.
FAQ
How long should my password be?
If it lives in a password manager, 16 or more characters with all sets enabled (about 104 bits) is plenty. If you have to remember it, use a passphrase of six or more words.
How is this different from a password made with Math.random()?
Math.random() is not designed for security and its output can be predictable. This tool uses the browser’s cryptographic random number generator (crypto.getRandomValues) and discards out-of-range values instead of using a plain remainder, so no character comes up more often than another (no modulo bias).
Are the passwords stored or sent anywhere?
No. They are generated in your browser on this device and disappear when you close the page.