Password Generator

Works fully offline Developer

Pick a length and which character sets to include, and get a cryptographically random password back — nothing generated here is ever transmitted or stored. A strength check is included below so you can also test a password of your own.

Type

Overview

A strong password is long and unpredictable, which is exactly what's hard to produce reliably by hand. This tool generates passwords using the browser's cryptographically secure random number generator rather than a predictable pseudo-random source, so the output is suitable for real account security, not just a placeholder.

Every generated password or passphrase is shown with its exact entropy, calculated from how it was built, and an estimate is available for any password you type into the checker further down the page — useful for judging an existing password without generating a new one.

Examples & Sample Data

16-character password with all character sets

Input
Length: 16, Uppercase + Lowercase + Numbers + Symbols
Output
aB3$kZ9!qW2#mN7p

Five-word passphrase

Input
Passphrase, 5 words, hyphen separator
Output
wolf-wrist-straw-chest-tacky (52 bits of entropy)

How It Works

  1. Choose Random password or Passphrase.
  2. For a password, pick a length and which character sets to include. Tick Avoid look-alikes if it will be read aloud or typed from paper.
  3. For a passphrase, pick how many words, a separator, and whether to capitalize words or add a number.
  4. Click Generate. The exact entropy of what was generated is shown underneath. Click again anytime for a new one with the same settings.
  5. Or type any password into the checker below to see an estimate of its strength as you type.

Tips & Best Practices

  • For a password you have to remember, such as a password manager's master password, a passphrase of six or more words is both strong and memorable.

Frequently Asked Questions

No. Passwords are generated and checked entirely in your browser — nothing you generate or type into the strength checker ever leaves your device.

Math.random() is not cryptographically secure and can be predictable. crypto.getRandomValues() is designed for security-sensitive uses like password generation.

The tool shows an error and won't generate a password — at least one character set (uppercase, lowercase, numbers, or symbols) must be selected.

Longer is generally stronger — most current guidance recommends at least 12–16 characters with a mix of character sets, especially for accounts without a password manager's length limit.

For something generated here, entropy is exact: length times log2 of the character pool for a password, or words times log2(1,296) for a passphrase. For a password you type into the checker, the pool is estimated from the character types present. That estimate can't recognize dictionary words or patterns, so a predictable password can score higher than it deserves.

Generally yes, but entropy alone can't detect a password that reuses a common phrase or pattern with high character variety. Avoid reusing passwords across sites regardless of the strength score, and prefer a password manager over memorizing unique passwords.

Yes. When a password is at least as long as the number of sets you picked, it's guaranteed to contain at least one character from each, so sites that require a digit or a symbol accept it. Those characters are shuffled into random positions.

They can be. Each word comes from the EFF short wordlist of 1,296 words and adds about 10.3 bits, so five words give 52 bits and six give 62. A passphrase is longer to type but far easier to remember, which suits a password manager's master password.

Related Tools

Explore more high-performance utilities.