Password Generator — Strong Random Passwords
A random password generator built on the browser's crypto RNG
Runs in your browser · nothing is uploaded
What it is
Pick a length and the kinds of characters you want, and the tool produces random passwords that are hard to guess. You can generate up to 100 at once and copy any of them with one click. Everything is computed in your browser and nothing is uploaded.
How to use
- Set the length with the slider (up to 128) or the number box, anywhere from 4 to 1024. The 16, 32, 64, 128, 256, 512 and 1024 buttons below jump straight to that length.
- Tick the character types you want: lowercase, uppercase, digits, symbols.
- Turn on the look-alike exclusion if you will have to copy the password by hand.
- Results refresh whenever you change an option. Press Generate again to draw a new set with the same options.
- Press Copy next to a password and paste it into your password manager or the sign-up form.
How it works
- Random source: only
crypto.getRandomValuesis used, neverMath.random. - No modulo bias: picking a character with
random % poolSizemakes some characters slightly more likely. Instead, any 32-bit value that falls in the uneven tail (the remainder of 2^32 divided by the pool size) is discarded and redrawn. This is rejection sampling, and every character ends up equally likely. - Every type present: one character from each selected type is drawn first, the rest come from the full pool, and the whole list is shuffled with the Fisher-Yates algorithm.
- Entropy: shown as length × log2(pool size). It is an approximation, because guaranteeing each type makes the true value very slightly lower.
- Strength labels: under 40 bits is weak, under 60 fair, under 80 good, and 80 or more very strong.
- Character pools: 26 lowercase, 26 uppercase, 10 digits and 25 symbols (
!@#$%^&*()-_=+[]{};:,.?/~).
Examples
| Settings | Pool size | Entropy | Label |
|---|---|---|---|
| 8 digits | 10 | about 26.6 bits | Weak |
| 12 letters and digits | 62 | about 71.4 bits | Good |
| 16 characters, all types | 87 | about 103.1 bits | Very strong |
| 24 characters, all types | 87 | about 154.6 bits | Very strong |
Using a different password on every site matters more than any single password’s length, so keep the generated ones in a password manager.
FAQ
Is the generated password sent or stored anywhere?
No. It is created inside your browser tab and never leaves it. It disappears when you close the page, so save it in a password manager right away.
Why not just use Math.random?
Math.random is not designed to be unpredictable. This tool calls crypto.getRandomValues, which draws on the operating system's cryptographically secure random source.
What do the entropy bits mean?
Entropy counts how many equally likely passwords an attacker would have to guess among, expressed as a power of two. Every extra bit doubles the search space. This tool labels anything at 80 bits or more as very strong.
When should I exclude look-alike characters?
When you will type the password by hand or read it aloud. It removes I, l, 1 and the digit 0 versus the letters O and o. The trade-off is a slightly smaller character pool and so slightly lower entropy.