Skip to content

Runs entirely in your browser. Nothing you paste leaves this page.

Free / No sign-up

Strong password generator: random and secure.

Generate cryptographically random passwords, choose the length and character sets, and see exactly how strong each one is in bits of entropy. Nothing is stored or sent.

Your password

Choose at least one character set
Very strong129 bits of entropy

20 characters × log₂(87) = 128.9 bits. Each extra bit doubles the guesses an attacker needs.

Characters

Strength scale

  • Weakunder 40 bitsCracked quickly if a hash ever leaks
  • Fair40 to 59 bitsHolds up only behind login rate limits
  • Strong60 to 79 bitsGood for most accounts
  • Very strong80 bits and upBeyond practical offline attacks

Generated with crypto.getRandomValues and unbiased sampling, so every character is equally likely. Passwords exist only in this tab: nothing is stored, logged or sent.

How to use it.

  1. 01

    Set the length. 16 or more characters is a good default; use the presets or type an exact number up to 128.

  2. 02

    Choose lowercase, uppercase, numbers and symbols, and optionally exclude look-alike characters.

  3. 03

    Copy the password, or pick one of the five alternatives below it, and save it in a password manager.

What it does.

Everything this tool handles, all of it inside your browser tab.

  • Cryptographically secure randomness from crypto.getRandomValues
  • Unbiased rejection sampling and a Fisher-Yates shuffle
  • Length from 6 to 128 characters, with presets for 12, 16, 20, 32 and 64
  • Lowercase, uppercase, numbers and symbols, each guaranteed when selected
  • Option to exclude look-alike characters such as I, l, 1, O and 0
  • Live entropy in bits with a strength rating
  • Six passwords per batch to choose from
  • Nothing is stored, logged or sent

Worked examples.

  • Entropy of common password lengths

    8 lowercase letters        8 × log₂(26) =  37.6 bits   Weak
    12 lowercase letters      12 × log₂(26) =  56.4 bits   Fair
    16 letters and digits     16 × log₂(62) =  95.3 bits   Very strong
    20 from all 87 characters 20 × log₂(87) = 128.9 bits   Very strong

    Length multiplies strength. Adding character sets helps, but adding characters helps more.

  • A 16-character password with symbols

    Length 16, a-z A-Z 0-9 and symbols (87 characters)
    16 × log₂(87) = 103.1 bits → Very strong
    
    Shape: q7#Vf2!mR9@xLp4&

    The shape is only an illustration. Never use a password you have seen published anywhere, including this one; generate your own above.

  • Excluding look-alike characters

    All sets, 87 characters:          20 chars = 128.9 bits
    Without I l 1 O 0 o S 5 Z 2 B 8:   20 chars = 124.6 bits
    Add one character, 75 characters:  21 chars = 130.8 bits

    Removing 12 characters costs about 4 bits at this length. One extra character more than makes up for it.

  • Generate a secure random password in code

    Python    import secrets; secrets.token_urlsafe(16)   # 16 random bytes, 22 characters
    OpenSSL   openssl rand -base64 24                   # 24 random bytes, 32 characters
    Browser   crypto.getRandomValues(new Uint32Array(1))  # secure random integers
    
    Never use Math.random() or Python's random module for secrets.

    Use the cryptographically secure source in your language. 16 random bytes is 128 bits of entropy.

What makes a password strong?

A strong password is one an attacker cannot guess, and the only reliable way to get that is randomness plus length. Attackers rarely type guesses into a login form. They take a leaked database of password hashes and test candidates offline at high speed, starting with words, names, dates, keyboard patterns and passwords from earlier breaches, then the same with common substitutions like @ for a and 1 for i.

That is why Summer2026! is weak despite having upper and lower case, a number and a symbol: it follows a pattern attackers try early. A randomly generated password has no pattern, so the attacker's only option is brute force across every possible combination. Reuse is the other big risk. When one site is breached, attackers try the same email and password everywhere else, so every account needs its own password.

Password entropy, explained

Entropy measures, in bits, how many guesses a brute-force attack needs. A password of length L chosen at random from a pool of N characters has L × log₂(N) bits, and every extra bit doubles the work. This generator's full pool has 87 characters (26 lowercase, 26 uppercase, 10 digits and 25 symbols), so each character adds about 6.4 bits: 16 characters give about 103 bits and 20 characters about 129.

To put numbers on it, assume an attacker can test a trillion (10¹²) guesses per second offline, a generous figure for a fast hash. 40 bits falls in about a second. 60 bits takes days. 80 bits takes tens of thousands of years on average, and 128 bits is out of reach for any conceivable hardware. The strength meter here rates under 40 bits as weak, 40 to 60 fair, 60 to 80 strong and 80 or more very strong.

The formula only applies to randomly generated passwords. A human-chosen password of the same length has far less real entropy, because people choose predictably. Strictly, guaranteeing one character from every chosen set removes a tiny fraction of combinations, so the true figure is a fraction of a bit lower than the formula; at 16 or more characters that is irrelevant.

How this password generator works

Every character comes from crypto.getRandomValues, the browser's cryptographically secure random number generator, which is seeded by the operating system. Math.random() is never used: it is fast but predictable and unsuitable for secrets.

Turning random numbers into characters has a classic trap called modulo bias: taking a random 32-bit number modulo 87 makes some characters slightly more likely than others. This generator uses rejection sampling, discarding the few values that would cause bias, so every character is exactly equally likely. It picks one character from each set you selected, fills the rest from the whole pool, then shuffles the result with a Fisher-Yates shuffle driven by the same secure source.

The symbol set is !@#$%^&*()-_=+[]{};:,.?/~, chosen to avoid quotes, backslashes and spaces that commonly break forms, shells and config files. Passwords exist only in this tab. Nothing is stored, logged or sent, and they disappear when you leave the page.

What do NIST password guidelines say?

NIST Special Publication 800-63B, the US government's digital identity guideline that many organisations worldwide follow, was revised in its fourth edition in 2025. It requires passwords of at least 15 characters when a password is the only authentication factor, and at least 8 when it is used as part of multi-factor authentication. Services should accept passwords of at least 64 characters and any printable character, including spaces and Unicode.

Revision 4 also says verifiers must not impose composition rules such as 'one uppercase letter, one number and one symbol', and must not force periodic password changes unless there is evidence of compromise. Instead, they should check new passwords against lists of breached and commonly used passwords and allow password managers and pasting. In short: length and randomness beat complexity rules, which matches what the entropy maths shows.

How long should a password be?

For accounts stored in a password manager, 16 to 20 random characters from all sets is a comfortable default: well over 100 bits, and you never type it. Use 20 or more for admin, cloud and financial accounts. Wi-Fi passwords (WPA2 and WPA3 personal) typically accept 8 to 63 characters; 20 or more random characters keeps offline attacks on a captured handshake impractical.

Some sites still cap length or reject certain symbols. Untick Symbols if a site refuses them and add four or five characters to make up the entropy. Exclude look-alikes when a password will be read aloud or typed from paper: it removes I, l, 1, O, 0, o, S, 5, Z, 2, B and 8, shrinking the pool to 75 characters, so add a character or two. For API keys, database credentials and signing secrets, use 32 or more characters, or generate keys with your platform's secret tooling.

Passwords vs passphrases vs passkeys

A passphrase of randomly chosen words, such as five or six words picked by dice from a 7,776-word list (about 12.9 bits per word), is easier to remember and type, which makes it a good choice for the one password you must memorise: your password manager's master password or a device login. It must be truly random; a favourite quote is not.

Passkeys go further. Built on FIDO2 and WebAuthn, they replace the password with a key pair stored on your device, so there is nothing to phish, reuse or leak from a server. Where passkeys are not offered, combine a unique generated password with multi-factor authentication. Our guide to sessions, JWTs and passkeys explains how to add them to your own app.

Storing passwords if you build software

If you run a service, never store passwords in plain text, encrypted or with a fast hash such as SHA-256. Use a slow, salted password-hashing function: Argon2id, or scrypt, bcrypt or PBKDF2 where required. The hash generator explains why fast hashes fail here. Rate-limit login attempts, screen new passwords against breach lists, and offer passkeys and MFA.

Questions, answered

Something else on your mind? Ask a consultant and get a reply within one business day.

Is it safe to generate passwords online?

Yes, when the generator uses crypto.getRandomValues and runs locally, as this one does. Passwords are never sent, stored or logged; leave or refresh the page and they are gone.

How long should a password be?

At least 15 characters when the password is your only protection, which is the current NIST minimum, and 16 to 20 random characters is a comfortable default. Length adds more strength than complexity rules, and a password manager means you never need to remember it.

Is a 12-character password strong enough?

A random 12-character password from all character sets has about 77 bits of entropy, which is strong. A human-chosen 12-character password is much weaker. For important accounts, use 16 or more random characters.

What is password entropy?

A measure in bits of how many guesses a brute-force attack needs: length × log₂(pool size) for a random password. Each extra bit doubles the guesses, and 80 bits or more is beyond realistic brute force.

Do passwords need symbols and numbers?

They help a little, but length matters more, and current NIST guidance says services should not force composition rules. If a site rejects symbols, untick them and add a few characters.

Why exclude look-alike characters?

Characters like l, 1 and I, or O and 0, are easy to misread when a password is typed from paper or read aloud. Excluding them reduces the pool slightly, so add a character or two to compensate.

Should I change my passwords regularly?

Not on a fixed schedule. NIST guidance says to change a password when there is evidence it has been compromised, not periodically, because forced changes lead to weaker, predictable passwords.

Is a passphrase better than a random password?

A random passphrase of five or six dictionary words is easier to remember and type and is strong enough for a master password. For everything stored in a password manager, a random 16 to 20 character password is shorter for the same strength.

Can I use this for Wi-Fi passwords or API keys?

Yes. Wi-Fi (WPA2 and WPA3 personal) typically accepts 8 to 63 characters, so 20 or more random characters is a good choice. For API keys and secrets, use 32 or more characters.

Where should I keep generated passwords?

In a password manager, with multi-factor authentication or a passkey on accounts that support it. Avoid spreadsheets, notes apps and reusing one password across sites.

More free tools.

All tools

Need tooling like this inside your product?

We build internal tools, developer platforms and APIs. Tell us what your team keeps doing by hand.