Skip to content
Cuisdev

Password Generator

Strong random passwords and passphrases, generated locally

  • Runs in your browser
  • No sign-up
  • Free forever
Loading the tool…

How to use the Password Generator

  1. 1

    Choose Password for a random string of characters or Passphrase for a series of random words.

  2. 2

    For a password, set the length and pick the character types: capitals, lower case, digits and symbols. Edit the symbol set if a site rejects some symbols.

  3. 3

    Turn on No look-alikes to leave out characters such as I, l, 1, O and 0, or No repeats to use each character once.

  4. 4

    Check the strength bar and the bits of entropy, then press Copy and paste the result straight into your password manager.

  5. 5

    Need several? Set a number under Bulk and press Generate to get up to 100 at once, with Copy all.

Features

  • Uses your browser's cryptographic random generator with unbiased sampling
  • Passwords from 4 to 128 characters with any mix of character types and a custom symbol set
  • Passphrases of 3 to 12 words from a list of over 2,300 common English words
  • Options to exclude look-alike characters, require every type, or avoid repeats
  • Entropy in bits, a strength rating and an estimated time to guess
  • Bulk generation of up to 100 passwords with copy all
  • Show and hide controls for every result
  • Nothing generated is uploaded, logged or saved; only your options are remembered

Why random beats clever

People are predictable. Passwords built from names, dates, keyboard patterns or a favourite word with a number on the end fall quickly to attacks that try the common patterns first. A password generator removes the human from the choice: every character or word is picked at random from a known pool, so the only way to find it is to try possibilities one by one.

This generator uses the browser’s cryptographic random number generator and picks each character with rejection sampling, which avoids the small bias a simple remainder calculation would introduce. When you require every character type, those characters are shuffled into random positions so they do not always sit at the start.

Passwords or passphrases

A random password packs the most strength into the fewest characters, which suits a password manager that types it for you. A passphrase trades length for usability: words separated by dashes are easy to read, say and type on a phone keyboard, which makes them a good choice for the one password you have to remember, such as the master password of your password manager or your computer login.

Whichever you choose, use a different password for every site. Reuse is what turns one breached site into many compromised accounts.

To create unique identifiers rather than secrets, use the UUID Generator. To check a file or message has not changed, compute its fingerprint with the Hash Generator.

Frequently asked questions

Is it safe to generate passwords in a browser?
Yes, when the generator uses the browser's cryptographic random source and runs locally, as this one does. Passwords are created with crypto.getRandomValues inside your tab, never sent over the network and never stored. Only your choices such as length and character types are saved on your device, so the page opens the way you left it.
How long should my password be?
For accounts protected by a password manager, 16 to 20 random characters with all four types gives well over 100 bits of entropy, far beyond any practical attack. For something you must type or remember, a passphrase of five or six random words is easier to handle and still strong.
Are passphrases really as strong as random passwords?
Strength comes from how many equally likely choices there are, not from how complicated something looks. Each word here is picked from more than 2,300 options and adds about 11 bits. Five words give about 56 bits and six give about 67, before any added number or symbol. The entropy figure shows the exact value for your settings.
What does entropy in bits mean?
It measures how many possibilities an attacker would have to try. Each extra bit doubles the work. The figure is calculated from the real size of the character pool or word list and the length, so it changes as you change the options. Fifty bits is fair, 60 or more is strong and 90 or more is very strong.
Why remove look-alike characters?
Characters such as capital I, lower-case l and the digit 1, or capital O and zero, are easy to misread when a password is written down or read aloud. Leaving them out costs a little entropy, which the strength figure accounts for, and saves typing errors.
How accurate is the time to guess?
It is an estimate. It assumes an attacker who has stolen a password hash and can try ten billion guesses a second, and it shows the average time to find yours. Real attacks vary a lot with the hashing method the site uses. A password reused on a site that leaks it in plain text is weak no matter how long it is, so use a different password everywhere.

Last updated .