Password generator

Choose the length and which characters may be used, and you get a list of strong random passwords straight away. They are made in your browser with your device's cryptographic random number generator and are never sent or stored anywhere.

Characters

How it works

  1. Choose your settings

    The number and, for passwords, the length and which characters are allowed.

  2. Ready at once

    Every change gives a new set. Click Generate new for another one.

  3. Copy or download

    Copy everything, only the first, or save the list as a text file.

How long should a password be?

Length matters most. The tool counts the possible characters and shows the entropy in bits: the length times the base-2 logarithm of the character set, rounded down. With all four sets ticked there are 86 characters (26 + 26 + 10 + 24 symbols), so every extra character adds about 6.4 bits.

Length Entropy The tool says
6 digits only about 19 bits weak
8 characters about 51 bits fair
12 characters about 77 bits strong
16 characters about 102 bits very strong
24 characters about 154 bits very strong

The labels change at 40, 60 and 80 bits. For e-mail, banking and your password manager, aim for 80 bits or more, which at 86 characters means at least 13 characters.

What you can set

  • Number (1 to 100) and Password length (4 to 128).
  • Lower case, Upper case, Digits and Symbols: tick the kinds that are allowed. Every kind you tick appears at least once, so the password also passes sites that demand a digit and a symbol.
  • Leave out look-alike characters (l, I, 1, O, 0) for passwords you read aloud or copy by hand.
  • Copy, Copy only the first and Download .txt. Generate new makes a fresh set, and changing an option does so too.

Tips for safe passwords

  • Use a different password for every site, so one leak doesn't open your other accounts.
  • Keep them in a password manager instead of trying to remember them.
  • Turn on two-step verification wherever you can.
  • Need an ID rather than a password? The UUID generator makes random identifiers, and the hash generator turns text into a fixed fingerprint.

Frequently asked questions

Which character sets should I tick?

All four, unless a site refuses some. Some sites reject symbols. In that case untick *Symbols (!#$%…)* and add length instead: 16 characters from letters and digits (62 possible) still give about 95 bits, which is "very strong".

Are the passwords really random?

Every character comes from `crypto.getRandomValues`, the random number generator your browser takes from the operating system and meant for cryptography. Each pick is made without bias, one character from every ticked set is guaranteed, and the result is shuffled so those guaranteed characters don't sit at the start.

Can a password still be weak if the tool says "very strong"?

Yes, if you reuse it. The bits describe how hard the password is to guess, not how safe the site that stores it is. A strong password used on two sites is only as safe as the weaker site. Use a different one everywhere and keep them in a password manager.

Why does *Leave out look-alike characters* matter?

It removes `l`, `I`, `i`, `1`, `L`, `o`, `O` and `0`, so a password you have to read aloud or type from a printout has no mix-ups. The set drops from 86 to 78 characters, so 16 characters give about 100 bits instead of 102, which is no real loss.

Are the passwords stored or sent anywhere?

No. They are made in your browser, shown in the box and gone when you close or reload the page. There is no account and nothing is uploaded.