Length: 16
Exclude characters
How it works
The Password Generator creates strong, random passwords using the browser's cryptographic random number generator — with control over length, character classes, and readability. Nothing is generated on a server and nothing is stored, so the password exists only in your tab until you copy it.
What makes a password strong is entropy — the number of guesses an attacker needs on average. Entropy grows with length far faster than with complexity: a 20-character lowercase passphrase is harder to crack than a 10-character password with symbols. That is why every modern guideline (including NIST SP 800-63B) now recommends long passwords over complicated short ones, and drops the old rules about forced periodic rotation and mandatory symbol classes.
Options available: - **Length**: 8–128 characters. 16 is a sensible default for accounts you type by hand; 32+ for anything stored in a password manager. - **Character sets**: lowercase, uppercase, digits, and symbols, each toggled independently. Every enabled set is guaranteed to appear at least once. - **Exclude ambiguous characters**: removes 0/O, 1/l/I, and similar look-alikes for passwords you will read aloud or retype from a screen. - **Passphrase mode**: joins random dictionary words with a separator (correct-horse-battery-staple style) — far easier to remember and type on a phone. - **Bulk generation**: produce up to 100 passwords at once for seeding test accounts or provisioning a team.
Entropy guidance: entropy in bits = length × log₂(alphabet size). A 16-character password from the full 94-character printable ASCII set carries about 105 bits — beyond the reach of any offline brute-force attack. A 4-word passphrase from a 7,776-word list carries about 52 bits, enough for accounts protected by rate limiting and two-factor authentication.
How to use it: set the length, toggle the character classes you need, and click Generate. Copy the result straight into your password manager. Generate a fresh password for every account — reuse is what turns one breached site into a compromise of everything else you own.
Privacy: generation uses window.crypto.getRandomValues(), the same cryptographically secure source browsers use for TLS. Passwords are never transmitted, never logged, and never leave your device.
Frequently Asked Questions
- 16 characters is a good baseline for accounts you type manually, and 32 or more for anything stored in a password manager. Length matters far more than complexity: a 16-character random password has roughly 105 bits of entropy, which is beyond any feasible offline brute-force attack. Adding symbols to a short password helps much less than adding four more characters to it.
- It uses window.crypto.getRandomValues(), the browser's cryptographically secure pseudorandom number generator — the same source used for TLS key material. It is not Math.random(), which is predictable from previous outputs and unsuitable for anything security-related. Generation happens in your tab, so no server ever sees the password.
- Use a random password stored in a password manager for everything you do not have to type from memory. Use a passphrase — four or more random words — for the handful you must remember and type by hand: your device login, your password manager's master password, and your disk encryption key. A four-word passphrase from a large word list carries around 52 bits of entropy, which is sufficient when the account is also protected by rate limiting and two-factor authentication.
- No. NIST withdrew that advice in SP 800-63B because forced rotation makes people pick weaker, predictable variations (Summer2025!, then Autumn2025!). Change a password when there is a reason to: a breach notification, a shared credential, or a device you no longer trust. A long unique password per site, kept in a password manager with two-factor authentication enabled, is stronger than any rotation schedule.