Password Generator
Generate strong passwords with cryptographically secure randomness
Presets
Options
Removes characters that are hard to tell apart visually, like 0/O, 1/l/I and 5/S — handy when typing by hand.
Strength
Offline brute-force time: Far beyond the age of the universe
4 × 26 + 26 + 10 + 24 = 86
Generated passwords
wgE$sZMIEH5O#_b-OqY0x++r=e=B%X2vuy/(34k&+EjSMQc^2&n2N9_[Et*z;vnqgW%MS{B%.=Lld^7H
Last updated: 2026-10-11
About this tool
Password strength comes down to two things: how random it is and how long it is. This tool draws from the browser WebCrypto interface — the only suitable source of randomness for passwords, since Math.random is a predictable pseudo-random generator whose output can be inferred. You can set the length and character sets, exclude look-alike characters such as 0 and O, and the tool reports the information entropy and an estimated offline brute-force time, so you can see concretely whether adding two characters or adding symbols helps more. Generation happens entirely on your device and no password ever crosses the network.
Features
Cryptographically secure randomness
Randomness comes from crypto.getRandomValues, not Math.random. The latter is predictable and unsuitable for generating credentials.
Configurable character sets
Uppercase, lowercase, digits and symbols can be combined freely to match any password policy.
Exclude look-alike characters
One click removes characters that are hard to tell apart, such as 0/O/o, 1/l/I and 5/S, making manual transcription easier.
Quantified strength
Information entropy in bits plus an estimated offline brute-force time, turning "is this strong enough" into a comparable number.
Quick presets
Strong, easy-to-type, digits-only PIN and extra long — four common configurations, one click each.
Bulk generation
Generate several passwords at once, useful for distributing credentials across accounts or test environments.
How to use
- 1
Set length and character sets
Choose a length, tick the character types you need, or apply a preset.
- 2
Optionally exclude look-alikes
If the password will be written down by hand, enable "exclude look-alike characters".
- 3
Check the strength estimate
The strength section reports entropy and crack time so you can decide whether to lengthen it.
- 4
Generate and copy
Click generate, then copy passwords individually or all at once.
Options
- Length
- Number of characters. Each extra character multiplies the difficulty, making it the most effective hardening step.
- How many
- How many passwords to generate at once.
- Character types
- Uppercase, lowercase, digits and symbols; at least one must be selected.
- Exclude look-alike characters
- Removes visually ambiguous characters for easier transcription, at the cost of a smaller character set.
Common use cases
- Generating a strong password for a new account
- Producing distinct passwords for a batch of test accounts
- Creating an easy-to-type password for a device you configure by hand, such as a router admin page
- Checking whether the password you currently use is strong enough
FAQ
Questions you may have about this tool
Are passwords generated here secure?
The randomness is: crypto.getRandomValues is supplied by the operating system and is the only source in a browser suitable for generating credentials. Do remember that security also depends on how you store the password — transmission and storage are usually the weaker links.
Why not use Math.random?
Math.random is a predictable pseudo-random generator: with knowledge of the seed, or enough observed output, subsequent values can be inferred. Passwords it produces look random but are meaningfully weaker. This tool errors out when WebCrypto is unavailable rather than falling back to Math.random — a silent downgrade would hand you a weak password without telling you.
Are the passwords logged or uploaded?
No. Generation happens entirely in browser memory, passwords are not sent to any server, and they are gone once you refresh the page. You can confirm there are no related requests in developer tools.
What does entropy mean?
Entropy measures how unpredictable a password is, in bits. Roughly speaking, each additional bit doubles the difficulty of cracking it. For important accounts, 60–80 bits is a reasonable target.
How accurate is the crack-time estimate?
It is an order-of-magnitude reference, not a precise prediction. It assumes a hypothetical offline brute-force speed; in reality it depends on the attacker hardware and whether the target throttles attempts. It is still reliable for comparing, say, a 16-character password against a 20-character one.
Does excluding look-alike characters reduce security?
Slightly, because the available character set shrinks. What you gain is transcribability — a strong password typed in wrong is worse than a medium one typed correctly. Enable it when a human has to type the password; skip it when it will only ever be copy-pasted.
How often should I change my password?
Modern guidance (such as NIST SP 800-63B) no longer recommends forced periodic rotation, since it encourages predictable minor edits. Better practice: use a long random password, make it unique per site, keep it in a password manager, and change it immediately if a breach occurs.
Can it make a PIN or a Wi-Fi password?
Yes. The digits-only PIN preset produces numeric passwords; for a device or guest network, the easy-to-type preset (no symbols, no look-alikes) is less error-prone when entered by hand.