Password generator
Generate strong random passwords in your browser.
Randomness that is actually random
Passwords here come from crypto.getRandomValues, the browser's cryptographically secure generator. That distinction is not academic: a generator seeded from the clock produces output that can be reconstructed by anyone who knows roughly when you generated it. The old version of this site had precisely that flaw in one of its two random tools while the other did it correctly.
Generation happens entirely on your device. A password generator that talks to a server has, by construction, transmitted your password before you have used it.
Length beats complexity
The arithmetic is unforgiving and consistently misunderstood. Each additional character multiplies the search space; adding symbol classes only widens the alphabet. A 20-character lowercase-only password is dramatically stronger than an 8-character one using every symbol on the keyboard — and it is far easier to type.
The entropy figure shown is length × log₂(alphabet size). Under about 60 bits is weak against a determined offline attack; 80 or more is comfortable; above 128 the password stops being the weakest part of anything.
Look-alike characters
The option to avoid l, I, 1, O and 0 exists for passwords that get read off a screen and typed elsewhere — a router label, a Wi-Fi card, a password dictated over the phone. It costs a little entropy and saves a great deal of frustration. Leave it off for anything going straight into a password manager.
Use a password manager
The honest advice: generate long random passwords, never reuse them, and let a manager remember them. The reason people reuse passwords is that memorising unique ones is impossible, and that reuse — not weak generation — is what actually causes account compromise.
Common questions
Are these passwords safe?
They come from the browser's cryptographic generator and are created on your device. Nothing is transmitted.
How long should a password be?
Sixteen characters minimum for anything that matters, twenty or more for important accounts. Length beats symbol variety.
Should I avoid look-alike characters?
Yes if it will be read off a screen and typed. No if it goes straight into a password manager.
What does the entropy figure mean?
Bits of randomness. Under 60 is weak, 80 is comfortable, above 128 the password is no longer the weak point.
Do you store the passwords?
No. There is no server involved at all.