Password Strength Checker
Check how strong a password is and get an entropy estimate in bits, plus tips on what to add. The check runs on your device and sends nothing you type.
Generate a strong random password with your browser's cryptographic generator. Set the length and character mix, then copy it. Nothing is sent anywhere.
Updated
Your browser is preparing the tool. It runs 100% locally.
Pick a length (4 to 64) and the character sets to include (uppercase, lowercase, numbers, symbols), and the tool builds a random password with your browser's cryptographically secure generator (Web Crypto), not Math.random. A 16-character password using all four sets has roughly 103 bits of entropy. The password is generated and shown only on your device and is never transmitted.
Set the length anywhere from 4 to 64 (it starts at 16), tick the character sets you want and a password appears. Click it to copy, or press Generate for a new one. A small strength read-out underneath shows how length and variety change the result.
You can trust the result because of where the randomness comes from. The tool uses crypto.getRandomValues, the same secure generator browsers use for encryption keys. Many simpler tools use Math.random, whose output is predictable and unsafe for secrets.
The tool builds a character pool from the boxes you tick (26 uppercase, 26 lowercase, 10 digits and 26 symbols), then fills each position by drawing a random number from the Web Crypto generator and mapping it onto that pool.
The strength label, from Very weak to Very strong, is a quick estimate based on the password's length and how many character classes it uses. Everything happens in the page and the password is never sent. Pressing Generate draws a new set of random numbers.
The character pool
The randomness comes from crypto.getRandomValues, the browser's cryptographically secure generator, which is seeded by the operating system and also used for encryption keys. The tool does not use Math.random, which is predictable and should never be used for secrets.
bits = length × log2(pool size)
(pool size = the character sets you switch on, added together)16 chars, all four sets (pool 88): 16 × log2(88) ≈ 103 bits12 chars, lowercase + digits only (pool 36): 12 × log2(36) ≈ 62 bitsThese entropy figures apply in full because the tool picks every character at random. Each extra bit doubles the number of guesses an attacker needs.
How length and pool size add up
The password is generated on your device and never transmitted. Generating it makes no network request at all.
Nothing is saved, and refreshing the page clears it. Copy it straight into your password manager.
No server is involved, so no log of what you generated exists anywhere.
| Length | 4 to 64 (default 16) |
|---|---|
| Character sets | Uppercase, lowercase, digits, symbols (toggle each) |
| Symbols | 26 common keyboard symbols |
| Randomness | Web Crypto getRandomValues (cryptographically secure) |
| Full pool size | Up to 88 characters |
| 16-char strength | About 103 bits with all sets on |
| Output | Click-to-copy, with a strength meter |
| Where it runs | In your browser; nothing is sent |
The strength label is a quick estimate from length and character classes, not a full audit. A 16-character random password from this tool is strong whatever label it shows.
The entropy figures assume you keep the first result. If you keep regenerating until one 'looks nicer', you are choosing among them, and that lowers the randomness. Use the one it gives you.
A generated password is only as safe as where you keep it. Store it in a password manager, not in a note, email or spreadsheet.
Mapping a 32-bit random number onto the character pool introduces a tiny modulo bias. At these pool sizes it makes no practical difference, but the tool doesn't claim perfect uniformity.
Create a different strong password for every site, so a breach at one doesn't expose the others.
Swap a password that turned up in a leak for a fresh random one in seconds.
Generate a long key for a router, hotspot or device where you can paste it in.
Produce the random strings your manager stores and fills in for you.
To remember a password without a manager, use the passphrase generator. For digits only, use the PIN generator. To grade a password you already have, use the password strength checker.
Every character comes from crypto.getRandomValues, the browser's cryptographically secure generator (never Math.random), and the password stays on your device.
Check how strong a password is and get an entropy estimate in bits, plus tips on what to add. The check runs on your device and sends nothing you type.
Generate random whole numbers in any range, with an option for no repeats. The numbers come from the browser's cryptographic random source, not Math.random.
Compress an image to JPEG with a quality slider and watch the file size drop as you drag, in your browser.
Combine several PDFs into one file in the order you choose, without leaving your browser.
Count words, characters, sentences and paragraphs as you type, with reading and speaking time alongside.
Fill in your page title, description, keywords and author, and the tool writes a block of HTML head meta tags you can paste, with the title, description, viewport and robots tags included. The block updates as you type.
Generate as many as you need at the top of the page. It runs on this device and needs no account.