Password Generator
Generate strong, secure, random passwords.
💡 Common Use Cases
- Create strong passwords for new accounts
- Generate test credentials for development environments
- Replace weak or reused passwords
- Create temporary passwords for new team members
Generate strong, random passwords that are actually secure
A good password is long, random, and unique to the account it protects. None of those requirements is satisfied by anything a human brain can comfortably invent. "Spring2024!" feels strong but is among the first passwords any attacker tries. "P@ssw0rd123" sits in every credential-stuffing wordlist. The only reliable way to create a strong password is to have a computer generate it randomly, and that is exactly what this Password Generator does — locally, in your browser, never transmitted anywhere.
How to use it
Choose your password length (16 characters is a common minimum for important accounts; 20+ is better; 32+ is excellent for the few high-value accounts that matter most). Toggle the character classes you want included — uppercase letters, lowercase letters, digits, symbols. Optionally exclude visually-similar characters (1/l/I, 0/O) if the password will need to be typed by hand from a printout. Click Generate. A new random password appears. Click again for another. Copy it directly to your clipboard.
What makes a password strong
The strength of a password comes from two things: length and entropy (randomness of each character). A 20-character password using only lowercase letters has 20 × log₂(26) ≈ 94 bits of entropy — more than enough to resist every brute-force attack possible with current computing technology. A 20-character password using upper, lower, digits, and symbols has about 130 bits of entropy. For comparison, a 256-bit key is the gold standard for cryptographic security, so 130 bits is overkill for password use cases.
Length matters more than complexity. A 30-character password of just lowercase letters is significantly stronger than a 10-character password with every symbol — because every added character multiplies the attacker's search space, and 30 letters give you 26³⁰ possibilities (a number with 43 digits), while 10 mixed chars give you ~10²⁰. The widely-quoted requirement to include "uppercase, lowercase, digits, and symbols" was useful when passwords were typically 8 characters, but for any password of 16+ characters, length-of-lowercase is dominant.
Length recommendations by account importance
- Throwaway accounts (forums, demo sites): 12 characters with mixed case and digits is fine
- Standard accounts (most services): 16 characters mixed
- Important accounts (email, banking, social media): 20+ characters mixed
- Critical accounts (master passwords, root access): 32+ characters or a long passphrase
Passphrases vs random strings
A long passphrase made of random dictionary words ("correct horse battery staple" — the famous XKCD example) has comparable entropy to a shorter random string and is easier to remember and type. Six random words from a 7,776-word list (the Diceware standard) gives about 77 bits of entropy — more than enough for most uses. Passphrases are the right choice for passwords you must type by hand frequently; random strings are the right choice for passwords stored in a password manager.
The number-one password rule
Use a password manager. Every modern operating system, web browser, and dedicated password-manager app can generate, store, and auto-fill strong unique passwords for every account. You should not be remembering or typing passwords for individual services — your password manager should be. The only password you remember is your master password (which should be a long passphrase) and the unlock PIN for your devices.
The reason this matters: even if one service you use suffers a breach and your password from that service is leaked, attackers cannot reuse it on any other service you use because every account has a different password. Credential stuffing — trying leaked passwords against other services — is one of the most common attack patterns, and it only works against users who reuse passwords.
What this tool generates
The generator uses the browser's cryptographically-secure random number generator (window.crypto.getRandomValues), the same source used for cryptographic key generation in modern web applications. Each password is produced independently — there is no seed, no sequence, no way to predict one password from another. The passwords are not saved, not logged, and not transmitted anywhere. Once you close the tab, every password ever generated is gone.
Two-factor authentication is still required
A strong password is necessary but not sufficient. Every important account should also have two-factor authentication (2FA) enabled — ideally a hardware security key (YubiKey or similar) or an authenticator app, not SMS (which can be intercepted via SIM-swap attacks). 2FA protects you even if your password is somehow compromised.
Privacy
Password generation runs entirely in your browser. No password is ever sent to a server, no password is logged, and no password is stored on our side. The tool is safe to use for any account, including the most sensitive.