Skip to content
Browse tools

Password Generator

Strong passwords and memorable passphrases, generated with your browser's cryptographic random source — never sent anywhere, never stored.

Your password
—
— —

⚙️ Options

Length
20

📊 How Strong Is This?

Entropy — bits of true randomness
Possible combinations — every equally likely
Offline cracking — at 100 billion guesses/sec
Online cracking — at 1,000 guesses/sec

These are averages against a brute-force attacker who knows your exact settings, and assumes half the keyspace must be searched. They describe the generator, not the site you use the password on — a service that leaks its database or stores passwords badly makes the strongest password irrelevant.

🔒 Generated entirely on your device. This page uses crypto.getRandomValues(), the browser's cryptographically secure random number generator — not Math.random(), which is predictable and must never be used for secrets. Nothing you generate is transmitted, logged or stored anywhere.
HOW IT WORKS

Length Beats Complexity

Password strength is measured in bits of entropy: how many yes/no questions an attacker would need to guess it. Each extra character multiplies the possibilities by the size of your character set, so adding length raises entropy far faster than adding exotic symbols to a short password. A 20-character lowercase-only password is dramatically stronger than an 8-character one using every symbol on the keyboard. That's also why passphrases work — five random words from a large list carry more entropy than most people's "complex" passwords, while remaining possible to actually remember. Crucially, the words must be chosen randomly by the generator; a phrase you invented yourself is far more predictable than it feels.

What else can you check?

These tools all work on the same connection and address data — pick whichever question you actually have.

Want to see the full path to a site? DNS, redirects, every hop, the CDN, TLS and the origin server. Want to know your public IP? See your IPv4 and IPv6 addresses, location, ISP and ASN. Want to check your tower & route? Live ping, speed, DNS, traceroute and a map of nearby points. Want to ping from around the world? Real latency from real probes across 12 countries, live on a map. Want to locate any IP address? City, region, country and coordinates for any public IP. Want to know if an IP is risky? Proxy, VPN, Tor, hosting and abuse-report indicators. Want to know if you're blacklisted? Check an address against major spam and abuse DNSBLs. Want to know who owns an IP? Network owner, ASN, CIDR range and abuse contact. Want to explore an AS number? Announced prefixes, BGP neighbours and registry details. Want to test your connection speed? Measure real download, upload, ping and jitter. Want to see what changed? Word-level diff between two blocks of text or code. Want to know if a DNS change is live yet? Compare answers from five independent public resolvers. Want to verify a domain's nameservers? Direct authoritative checks, glue records and SOA serials. Want to check a domain's DNSSEC setup? DNSKEY, DS records, signature expiry and real validation. Want to see the hop-by-hop path to a server? A real traceroute from a genuine probe anywhere in the world. Want to know if a server port is open? A real TCP connection attempt - open, closed or filtered. Want to measure latency to a server? Real connect timing - min/avg/max, jitter and connection loss. Want a clean URL slug from a title? Real transliteration, stop words and batch mode. Want to find and replace across a document? Regex, capture groups and a live preview before you commit. Want to find the invisible character? Code points, escapes, bytes and hidden-character detection. Want to escape text for HTML? Minimal, named or numeric entities, attribute-safe. Want to strip emoji cleanly? Whole clusters - no half-flags or stray modifiers left. Want to spot repeated words? Frequency, density and accidental doubles like "the the". Want to know if a URL is cached? Two requests prove whether your CDN is really caching it. Want to see what a site knows about you? Storage, cookies, tokens and what your browser actually cached. Want to run that check on any site? One-click bookmarklet reads storage and tokens where they live. Want to know who your site talks to? Renders the page and names every outside company it contacts. Is your site one address or four? www, non-www, http and https - which serve, which redirect. Need to build an Authorization header? Basic, Bearer, API key, Digest and AWS SigV4 - signed in your browser. Want to tidy up a messy SQL query? Beautify, minify, lint and convert keyword casing for six dialects. Need to work out a percentage? Nine calculators covering every way a percentage gets asked. Want to work out a rise or a raise? Increases, growth, compounding and CAGR, with the working shown. Want to work out a discount or a drop? Discounts, stacked sales and depreciation, with the working shown. What is actually on that page? Words, reading time, readability, every image, embed and link. Need a favicon that works everywhere? Every size, a real multi-resolution .ico, and the tags to paste. What headers does a site send back? Every response header on every redirect hop, explained. Need to test a regular expression? Live matches, capture groups, replace preview and code snippets. Need a JPG as a PNG? Batch convert in your browser, with optional transparent background. Need somewhere to jot things down? Private notes, links, to-dos and reminders saved in your browser. Need just some pages of a PDF? Split by page, range or chunk, or extract the pages you pick. What is hiding inside that image? EXIF camera settings, GPS tags, colour palette and web checks.
COMMON QUESTIONS

Password Generator FAQ

Is it safe to generate a password on a website?

On this one, yes — because nothing leaves your browser. The generation happens in JavaScript on your device using the Web Crypto API, and no password is ever sent to our server, logged, or stored. You can verify that by opening your browser's network tab and generating one: there is no request.

Why not use Math.random()?

Because it's a fast statistical generator, not a secure one — its output can be predicted from previous values. This page uses crypto.getRandomValues(), which draws from the operating system's cryptographic entropy pool and is designed for exactly this purpose.

How many bits of entropy do I actually need?

As a rough guide: under 50 bits is weak, 60–80 is fine for most accounts with rate limiting, and 100+ is appropriate for password-manager master passwords, encryption keys and anything protecting other secrets. The meter above shows the real figure for your current settings.

Are passphrases really as strong as random passwords?

They can be, if the words are randomly chosen and there are enough of them. Five random words from a 7,776-word list gives about 64 bits — comparable to a 10-character fully random password, but far easier to type and remember. Six or seven words gets you well past most random passwords people would tolerate.

Should I use a different password for every site?

Yes, and this is more important than any single password's strength. Reused passwords are how one breached site becomes ten compromised accounts. A password manager makes this practical — you only need to remember its master passphrase.