Password generator
Make strong random passwords or memorable passphrases, choose exactly which characters to use, and see how strong the result really is.
- 100% free
- Runs in your browser
- No uploads
Password
Making a password…
Made on your device with your browser's secure random generator. Nothing is saved or sent.
- Runs on your deviceEvery tool works directly in your browser. No files are uploaded.
- Your privacy mattersYour files never leave your device, so there's nothing for us to store.
- No limitsUse any tool as much as you need. No daily caps, no waiting.
- Completely freeNo signup and no trial to cancel. Ads keep the tools free.
How to generate a strong password
- Choose password or passphrase. A password is a random string of characters; a passphrase is a few random words.
- Set the length and characters. Pick the types of characters a site accepts. Untick symbols or edit the list if a site rejects some of them.
- Copy it into your password manager. Make one, or a list of 10 to choose from. Press Generate new for a fresh set.
How the passwords are made
Every character is picked with your browser's cryptographically secure random generator (crypto.getRandomValues). Two details keep the result unbiased:
- No modulo bias. Turning a random number into one of, say, 87 characters with a simple remainder would make some characters slightly more likely. Random values from the uneven end of the range are thrown away and drawn again, so every character has exactly the same chance.
- “At least one of each” without shortcuts. Many generators force one character of each type into the password, which makes passwords with exactly one digit more likely than they should be. Here the whole password is drawn at random and simply drawn again if a chosen type is missing, so every valid password is equally likely.
The strength figure counts exactly how many passwords your settings allow, minus those missing a required type. For passphrases it's the number of words times log2(1,296).
Strength at a glance
| Settings | Entropy | Rating |
|---|---|---|
| 8 characters, all four types | about 50 bits | Fair |
| 12 characters, all four types | about 77 bits | Strong |
| 16 characters, all four types | about 103 bits | Very strong |
| 5-word passphrase | about 52 bits | Fair |
| 8-word passphrase | about 83 bits | Very strong |
Wordlist credit
Passphrases use the EFF short wordlist 1 by the Electronic Frontier Foundation: 1,296 short, common English words picked to be easy to remember and type. It is used unchanged under the Creative Commons Attribution 3.0 licence.
Frequently asked questions
Is it safe to generate a password on a website?
This page makes passwords inside your browser with the Web Crypto API, the same secure random number generator browsers use for encryption. Nothing is sent to a server or saved; once you leave the page the passwords are gone. You can load the page, disconnect from the internet, and it still works.
How long should my password be?
For a random password with all four character types, 16 characters gives about 100 bits of entropy, far beyond what can be guessed. Twelve is a reasonable minimum for accounts protected by rate limits. For a password manager's master password or disk encryption, a passphrase of 6 or more words is easier to type and remember.
What does bits of entropy mean?
It measures how many different passwords the generator could have produced with your settings: each extra bit doubles the number. 60 bits is about a million million million possibilities. The estimate assumes the attacker knows exactly how the password was made, which is the honest way to rate a random password.
Is a passphrase as strong as a random password?
It can be. Each word from the 1,296-word list adds about 10.3 bits, so five words give about 52 bits and seven give about 72, similar to an 11-character random password using letters, digits and symbols. Passphrases are longer to type but much easier to remember and to read out.
Why exclude look-alike characters?
Characters like 0 and O, or 1, l, I and |, are hard to tell apart in many fonts. If you'll ever copy a password by hand, from a printout or another screen, leaving them out avoids mistakes. It removes 7 characters from the pool, which costs very little strength.