Skip to main content

Password Generator

Generate strong passwords with cryptographically secure randomness

WebCrypto secure randomnessEntropy and crack-time estimatesPasswords never leave your browser

Presets

Options

Removes characters that are hard to tell apart visually, like 0/O, 1/l/I and 5/S — handy when typing by hand.

Entropy: 103 bits

Strength

Strong102.8 bits

Offline brute-force time: Far beyond the age of the universe

4 × 26 + 26 + 10 + 24 = 86

Generated passwords

  • wgE$sZMIEH5O#_b-
  • OqY0x++r=e=B%X2v
  • uy/(34k&+EjSMQc^
  • 2&n2N9_[Et*z;vnq
  • gW%MS{B%.=Lld^7H

Last updated: 2026-10-11

About this tool

Password strength comes down to two things: how random it is and how long it is. This tool draws from the browser WebCrypto interface — the only suitable source of randomness for passwords, since Math.random is a predictable pseudo-random generator whose output can be inferred. You can set the length and character sets, exclude look-alike characters such as 0 and O, and the tool reports the information entropy and an estimated offline brute-force time, so you can see concretely whether adding two characters or adding symbols helps more. Generation happens entirely on your device and no password ever crosses the network.

Features

Cryptographically secure randomness

Randomness comes from crypto.getRandomValues, not Math.random. The latter is predictable and unsuitable for generating credentials.

Configurable character sets

Uppercase, lowercase, digits and symbols can be combined freely to match any password policy.

Exclude look-alike characters

One click removes characters that are hard to tell apart, such as 0/O/o, 1/l/I and 5/S, making manual transcription easier.

Quantified strength

Information entropy in bits plus an estimated offline brute-force time, turning "is this strong enough" into a comparable number.

Quick presets

Strong, easy-to-type, digits-only PIN and extra long — four common configurations, one click each.

Bulk generation

Generate several passwords at once, useful for distributing credentials across accounts or test environments.

How to use

  1. 1

    Set length and character sets

    Choose a length, tick the character types you need, or apply a preset.

  2. 2

    Optionally exclude look-alikes

    If the password will be written down by hand, enable "exclude look-alike characters".

  3. 3

    Check the strength estimate

    The strength section reports entropy and crack time so you can decide whether to lengthen it.

  4. 4

    Generate and copy

    Click generate, then copy passwords individually or all at once.

Options

Length
Number of characters. Each extra character multiplies the difficulty, making it the most effective hardening step.
How many
How many passwords to generate at once.
Character types
Uppercase, lowercase, digits and symbols; at least one must be selected.
Exclude look-alike characters
Removes visually ambiguous characters for easier transcription, at the cost of a smaller character set.

Common use cases

  • Generating a strong password for a new account
  • Producing distinct passwords for a batch of test accounts
  • Creating an easy-to-type password for a device you configure by hand, such as a router admin page
  • Checking whether the password you currently use is strong enough

FAQ

Questions you may have about this tool

Are passwords generated here secure?

The randomness is: crypto.getRandomValues is supplied by the operating system and is the only source in a browser suitable for generating credentials. Do remember that security also depends on how you store the password — transmission and storage are usually the weaker links.

Why not use Math.random?

Math.random is a predictable pseudo-random generator: with knowledge of the seed, or enough observed output, subsequent values can be inferred. Passwords it produces look random but are meaningfully weaker. This tool errors out when WebCrypto is unavailable rather than falling back to Math.random — a silent downgrade would hand you a weak password without telling you.

Are the passwords logged or uploaded?

No. Generation happens entirely in browser memory, passwords are not sent to any server, and they are gone once you refresh the page. You can confirm there are no related requests in developer tools.

What does entropy mean?

Entropy measures how unpredictable a password is, in bits. Roughly speaking, each additional bit doubles the difficulty of cracking it. For important accounts, 60–80 bits is a reasonable target.

How accurate is the crack-time estimate?

It is an order-of-magnitude reference, not a precise prediction. It assumes a hypothetical offline brute-force speed; in reality it depends on the attacker hardware and whether the target throttles attempts. It is still reliable for comparing, say, a 16-character password against a 20-character one.

Does excluding look-alike characters reduce security?

Slightly, because the available character set shrinks. What you gain is transcribability — a strong password typed in wrong is worse than a medium one typed correctly. Enable it when a human has to type the password; skip it when it will only ever be copy-pasted.

How often should I change my password?

Modern guidance (such as NIST SP 800-63B) no longer recommends forced periodic rotation, since it encourages predictable minor edits. Better practice: use a long random password, make it unique per site, keep it in a password manager, and change it immediately if a breach occurs.

Can it make a PIN or a Wi-Fi password?

Yes. The digits-only PIN preset produces numeric passwords; for a device or guest network, the easy-to-type preset (no symbols, no look-alikes) is less error-prone when entered by hand.