Password Generator
Strong passwords and memorable passphrases, generated with your browser's cryptographic random source — never sent anywhere, never stored.
📊 How Strong Is This?
These are averages against a brute-force attacker who knows your exact settings, and assumes half the keyspace must be searched. They describe the generator, not the site you use the password on — a service that leaks its database or stores passwords badly makes the strongest password irrelevant.
crypto.getRandomValues(), the browser's cryptographically secure random number generator — not Math.random(), which is predictable and must never be used for secrets. Nothing you generate is transmitted, logged or stored anywhere.
Length Beats Complexity
Password strength is measured in bits of entropy: how many yes/no questions an attacker would need to guess it. Each extra character multiplies the possibilities by the size of your character set, so adding length raises entropy far faster than adding exotic symbols to a short password. A 20-character lowercase-only password is dramatically stronger than an 8-character one using every symbol on the keyboard. That's also why passphrases work — five random words from a large list carry more entropy than most people's "complex" passwords, while remaining possible to actually remember. Crucially, the words must be chosen randomly by the generator; a phrase you invented yourself is far more predictable than it feels.
What else can you check?
These tools all work on the same connection and address data — pick whichever question you actually have.
Password Generator FAQ
Is it safe to generate a password on a website?
On this one, yes — because nothing leaves your browser. The generation happens in JavaScript on your device using the Web Crypto API, and no password is ever sent to our server, logged, or stored. You can verify that by opening your browser's network tab and generating one: there is no request.
Why not use Math.random()?
Because it's a fast statistical generator, not a secure one — its output can be predicted from previous values. This page uses crypto.getRandomValues(), which draws from the operating system's cryptographic entropy pool and is designed for exactly this purpose.
How many bits of entropy do I actually need?
As a rough guide: under 50 bits is weak, 60–80 is fine for most accounts with rate limiting, and 100+ is appropriate for password-manager master passwords, encryption keys and anything protecting other secrets. The meter above shows the real figure for your current settings.
Are passphrases really as strong as random passwords?
They can be, if the words are randomly chosen and there are enough of them. Five random words from a 7,776-word list gives about 64 bits — comparable to a 10-character fully random password, but far easier to type and remember. Six or seven words gets you well past most random passwords people would tolerate.
Should I use a different password for every site?
Yes, and this is more important than any single password's strength. Reused passwords are how one breached site becomes ten compromised accounts. A password manager makes this practical — you only need to remember its master passphrase.