How it works
The generator uses crypto.getRandomValues(), the browser’s cryptographically secure random number source, with unbiased sampling, so every character is equally likely. It guarantees at least one character from every type you select, then shuffles the result. Nothing is sent to our server, logged or stored.
Options
- Length: 6 to 64 characters. 16+ is recommended.
- Character types: uppercase, lowercase, digits and symbols.
- Avoid look-alikes: removes characters that are easy to confuse (
l,1,I,O,0,o). Useful if you’ll read the password aloud or type it from paper.
What the strength meter means
Strength is shown as entropy in bits: length × log₂(size of the character set). Each extra bit doubles the number of guesses an attacker needs.
| Entropy | Rating | Example |
|---|---|---|
| Under 40 bits | Weak | 6 lowercase letters |
| 40–60 bits | Fair | 10 letters and digits |
| 60–80 bits | Strong | 12 characters, all types |
| 80+ bits | Very strong | 16+ characters, all types |
This assumes the password is truly random, which it is here. Human-chosen passwords are much weaker than their length suggests.
Password habits that matter most
- Use a different password for every account. Reused passwords are how one breach becomes many.
- Use a password manager to store them, so you only remember one strong master password.
- Turn on two-factor authentication, ideally with an authenticator app or passkey.
- Change passwords after a breach, not on a fixed schedule.
Frequently asked questions
Is it safe to generate a password on a website?
This generator runs entirely in your browser using the Web Crypto API's cryptographically secure random numbers. The password is never sent over the network or saved. You can even load the page and then go offline to generate one.
How long should my password be?
For accounts protected by a password manager, 16–20 random characters is plenty. For a password you must type by hand, a longer passphrase of random words is easier to remember and type.
Last updated