Secure Password Generator
Generate strong, random passwords in your browser, using cryptographic randomness.
Passwords never leave your browser
Generated passwords never leave your browser. They are created on your device and are not sent over the network, stored on a server or written to a log. You can disconnect from the internet after the page loads and keep generating passwords.
That is also why there is no history: reload the page and the generated passwords are gone. Copy what you need before you leave.
How the passwords are generated
The tool uses crypto.getRandomValues(), the Web Crypto API source of randomness intended for cryptographic use. It is not the same as ordinary pseudorandom functions such as Math.random(), which are predictable enough to be unfit for anything security-related.
You choose the length, from 8 to 128 characters, and which sets to include: uppercase, lowercase, digits and symbols. When a set is ticked, the password gets at least one character from it, which avoids the awkward result of asking for digits and receiving a password without any.
You can also exclude visually similar characters such as 0, O, 1, l and I, which helps when a password has to be read aloud, copied off a screen or typed by hand.
What makes a password strong
Password length is one of the most important factors in password strength. Each extra character multiplies the number of possible combinations, whereas swapping a letter for a symbol only adds a few options. A long random password resists guessing better than a short one full of creative substitutions.
Predictable substitutions help less than they appear to. Turning "a" into "@" or "o" into "0" is exactly what cracking tools try first, because those are well-known human patterns.
For accounts that matter, use a password that is long, unique and never reused. Keep credentials in a password manager and turn on multi-factor authentication wherever it is offered — it still protects you in the cases where the password does leak.
What entropy means
Entropy measures, in bits, the size of the space a randomly generated password is drawn from. Each additional bit doubles the number of combinations: a 60-bit password has twice the possibilities of a 59-bit one.
The value depends on two things: the size of the character set and, above all, the length. The indicator above is there to compare settings — it shows what raising the length does next to what adding symbols does.
The crack-time estimate assumes a fixed rate of one trillion guesses per second and reports the average case, half the search space. Real time depends on the attack method, the hardware, and above all on how the service stores the password: a slow, salted hash changes the arithmetic by orders of magnitude. Read the number as a comparison between settings, not as a prediction.
Why not to reuse passwords
When one password serves several services, a breach at any one of them puts all the others at risk. The attack has a name: credential stuffing, where lists of email and password pairs leaked from one site are tried automatically against dozens of others.
A different random password per service breaks that chain. Since nobody memorises dozens of them, a password manager stops being a convenience and becomes the thing that makes the practice possible.
Frequently asked questions
What is a good password length?
For accounts protected by a password alone, 16 random characters is a practical choice with comfortable margin, provided the service accepts that length. For anything more sensitive, raising the length is the most effective adjustment.
Do letters, digits and symbols make a password safer?
They widen the set of combinations, but the effect is modest next to length. Given the choice between adding symbols and adding characters, adding characters buys more. Symbols still matter when a service explicitly demands each type.
Do I need to change my password periodically?
Not without a sign of compromise. Current NIST guidance advises against arbitrary expiry precisely because it produces worse passwords: forced to change, people make predictable edits such as bumping the number on the end. Change it when you suspect a leak, and in that case change it at once.
Can I use the same password on several sites?
No. One breach is enough to expose every account sharing that password. Use a unique password per account and keep them in a manager.
What is the "Avoid Ambiguous" option for?
It removes visually similar characters such as 0, O, 1, l and I. It is worth using when the password will be read off a screen, dictated or typed by hand — a Wi-Fi password, for instance. The smaller set lowers entropy slightly; make it up with a few more characters.
Is the estimated crack time exact?
No. It is a mathematical estimate from a fixed guess rate. A real attack depends on the hardware, the storage algorithm and the method used, and frequently does not attempt pure brute force at all: it starts from leaked password lists and common human patterns.
Is generating several passwords at once safe?
Yes. Each password is generated independently from the same cryptographic source, and generating five makes none of them more predictable. The option exists for when you need credentials for several services at once.
Need to check other parameters of your infrastructure quickly? Use the IPv4 subnet calculator