Password Generator
Generate strong random passwords locally, with tunable character classes.
Runs entirely in your browser.
Your data never leaves this device and is never sent to our servers.
Passwords
Strength
Password strength is length and unpredictability, not decoration. A long passphrase of random words beats a short string with a symbol bolted on. This generator uses your browser cryptographic random source and reports entropy in bits so you can judge the result honestly.
How to use it
- Set the length — 16 characters or more is a sensible floor.
- Choose which character classes to include.
- Generate, then store the result in a password manager.
Not working as you expect? Report a problem with this tool.
Frequently asked questions
Are these passwords sent anywhere?
No. They are generated in your browser with crypto.getRandomValues and never transmitted. A password that travelled over the network to be created would not be a secret.
What does the entropy figure mean?
Bits of unpredictability. Under 50 is weak, 75 or more is strong, and above 110 is beyond brute force for the foreseeable future. It is a more honest measure than composition rules.
Should I exclude look-alike characters?
Only if the password will be typed from something printed. It slightly reduces entropy, so leave it off for anything stored in a password manager.