1. Home
  2. Barcode & Generate
  3. Password Generator

Password Generator

Strong random passwords from a cryptographic RNG, with entropy shown.

Runs in your browser · No upload Works offline
8–128 characters
1–20
Your password
—
Length 16 × log₂(90) ≈ 103.9 bits
Character pool
90 chars
Entropy
103.9 bits
Strength
Very strong

Passwords are generated on this device with crypto.getRandomValues() and are never sent or stored anywhere.

How to use

  1. Set the length (16 by default) and pick character sets: uppercase, lowercase, digits, symbols. Every set you pick is guaranteed at least one character.
  2. If you will ever type the password by hand, turn on Exclude look-alikes (I l 1 O 0 o). If a site rejects certain symbols, list them under Also exclude.
  3. Choose how many (1–20) and the passwords appear instantly. Hit Regenerate for a fresh batch and Copy next to the one you want.

Entropy and strength

Entropy measures how hard a random password is to guess, in bits: length × log₂(pool size). Each extra bit doubles the number of possible passwords.

Character sets Pool 12 chars 16 chars 20 chars
Digits only 10 39.9 bits 53.2 bits 66.4 bits
Lowercase only 26 56.4 bits 75.2 bits 94.0 bits
Upper + lower + digits 62 71.5 bits 95.3 bits 119.1 bits
All, with 28 symbols 90 77.9 bits 103.9 bits 129.8 bits

The strength label is this tool’s own scale: under 40 bits very weak, under 60 weak, under 80 fair, under 100 strong, 100 and above very strong. These numbers only hold for randomly generated passwords, not ones a person made up.

Why length beats complexity

Adding symbols to a 16-character password (pool 62 → 90) raises entropy from 95.3 to 103.9 bits — 8.6 bits. Keeping letters and digits and adding just two more characters does better (18 chars = 107.2 bits). Forced-symbol rules mostly push people toward patterns like Password1!, which is why NIST’s Digital Identity Guidelines (SP 800-63B) favor adequate length and screening against breached-password lists over composition rules.

Passphrases and password managers

  • Passphrases: for the few passwords you must memorize — your computer login, your password manager’s master password — string together several randomly chosen words. Picking from the 7,776-word Diceware list gives about 12.9 bits per word, so six words is roughly 77.5 bits. A sentence you invent yourself is not random and is much weaker.
  • Password managers: using a different password on every site matters most, because passwords leaked from one site are routinely tried on others. Nobody can memorize dozens of them, so let a manager store them, and turn on two-factor authentication for important accounts.
  • Need random identifiers instead? Try the UUID generator. To hash a string, use the hash generator.

FAQ

How long should my password be?

If it lives in a password manager, 16 or more characters with all sets enabled (about 104 bits) is plenty. If you have to remember it, use a passphrase of six or more words.

How is this different from a password made with Math.random()?

Math.random() is not designed for security and its output can be predictable. This tool uses the browser’s cryptographic random number generator (crypto.getRandomValues) and discards out-of-range values instead of using a plain remainder, so no character comes up more often than another (no modulo bias).

Are the passwords stored or sent anywhere?

No. They are generated in your browser on this device and disappear when you close the page.

Coming soon

Can't find the tool you need?

Tell us what you want to do. We build the most requested tools first.