Password Generator

Generate a strong random password with your browser's cryptographic generator. Set the length and character mix, then copy it. Nothing is sent anywhere.

Updated

Password ToolsPopularHot● Free No upload Instant
Km7#xQ3!

Loading Password Generator…

Your browser is preparing the tool. It runs 100% locally.

Quick answer

Pick a length (4 to 64) and the character sets to include (uppercase, lowercase, numbers, symbols), and the tool builds a random password with your browser's cryptographically secure generator (Web Crypto), not Math.random. A 16-character password using all four sets has roughly 103 bits of entropy. The password is generated and shown only on your device and is never transmitted.

  • 4 to 64length range
  • 88characters in the full pool
  • ~103 bits16 chars, all sets
  • 0network requests

What the Password Generator does

Set the length anywhere from 4 to 64 (it starts at 16), tick the character sets you want and a password appears. Click it to copy, or press Generate for a new one. A small strength read-out underneath shows how length and variety change the result.

You can trust the result because of where the randomness comes from. The tool uses crypto.getRandomValues, the same secure generator browsers use for encryption keys. Many simpler tools use Math.random, whose output is predictable and unsafe for secrets.

How it works

The tool builds a character pool from the boxes you tick (26 uppercase, 26 lowercase, 10 digits and 26 symbols), then fills each position by drawing a random number from the Web Crypto generator and mapping it onto that pool.

The strength label, from Very weak to Very strong, is a quick estimate based on the password's length and how many character classes it uses. Everything happens in the page and the password is never sent. Pressing Generate draws a new set of random numbers.

The character pool

A-Z26a-z260-910symbols26= 88
Every box you untick shrinks the pool each character is drawn from.

Generation algorithm

The randomness comes from crypto.getRandomValues, the browser's cryptographically secure generator, which is seeded by the operating system and also used for encryption keys. The tool does not use Math.random, which is predictable and should never be used for secrets.

  1. Step 1. Build the character pool from the sets you enable (uppercase 26, lowercase 26, digits 10, symbols 26).
  2. Step 2. For each of the N positions, draw a random value from the Web Crypto generator.
  3. Step 3. Map that value onto the pool and take the character at that index.
  4. Step 4. Show the finished password with a quick strength read-out based on length and variety.
  5. Step 5. Press Generate for a new one, or click the password to copy it.

Password entropy

bits = length × log2(pool size) (pool size = the character sets you switch on, added together)
Worked examples
16 chars, all four sets (pool 88): 16 × log2(88) ≈ 103 bits
12 chars, lowercase + digits only (pool 36): 12 × log2(36) ≈ 62 bits

These entropy figures apply in full because the tool picks every character at random. Each extra bit doubles the number of guesses an attacker needs.

How length and pool size add up

05010015012 chars, a-z + 0-9≈ 62 bits16 chars, a-z only≈ 7512 chars, all four sets≈ 7816 chars, all four sets≈ 10320 chars, all four sets≈ 129
bits = length × log2(pool). Four more characters from the full pool add about 26 bits.

Privacy

The password is generated on your device and never transmitted. Generating it makes no network request at all.

Nothing is saved, and refreshing the page clears it. Copy it straight into your password manager.

No server is involved, so no log of what you generated exists anywhere.

Technical details

Length4 to 64 (default 16)
Character setsUppercase, lowercase, digits, symbols (toggle each)
Symbols26 common keyboard symbols
RandomnessWeb Crypto getRandomValues (cryptographically secure)
Full pool sizeUp to 88 characters
16-char strengthAbout 103 bits with all sets on
OutputClick-to-copy, with a strength meter
Where it runsIn your browser; nothing is sent

Standards and references

  • NIST SP 800-63B: current US guidance: prefer length over complexity, require at least 15 characters for a password used on its own, allow at least 64, and don't force composition rules.
  • Web Crypto: getRandomValues: the browser API for cryptographically secure random values. This tool uses it for every character.
  • Entropy (bits): the standard measure of unpredictability, length × log2(pool). Each bit doubles the guesses required.

Accuracy and limits

The strength label is a quick estimate from length and character classes, not a full audit. A 16-character random password from this tool is strong whatever label it shows.

The entropy figures assume you keep the first result. If you keep regenerating until one 'looks nicer', you are choosing among them, and that lowers the randomness. Use the one it gives you.

A generated password is only as safe as where you keep it. Store it in a password manager, not in a note, email or spreadsheet.

Mapping a 32-bit random number onto the character pool introduces a tiny modulo bias. At these pool sizes it makes no practical difference, but the tool doesn't claim perfect uniformity.

Real-world uses

New account sign-ups

Create a different strong password for every site, so a breach at one doesn't expose the others.

Replacing a breached password

Swap a password that turned up in a leak for a fresh random one in seconds.

Wi-Fi and device passwords

Generate a long key for a router, hotspot or device where you can paste it in.

Filling a password manager

Produce the random strings your manager stores and fills in for you.

When it fits, and when it doesn't

Good for

  • A unique password for each website or app
  • Maximum strength when you don't need to memorise it
  • Anything you'll store in a password manager
  • Replacing a weak or reused password

Not the best choice for

  • A password you must often type from memory
  • A numeric PIN for a phone or card
  • Testing a password you already have

To remember a password without a manager, use the passphrase generator. For digits only, use the PIN generator. To grade a password you already have, use the password strength checker.

Tips and tricks

What we would do

Frequently asked questions

Is this random enough to be safe?
Yes. It uses crypto.getRandomValues, the browser's cryptographically secure generator, the same kind of randomness used to create encryption keys. Earlier results don't let anyone predict the next one.
Does it use Math.random?
No. Math.random is fast but predictable and unsuitable for security, so this tool uses the Web Crypto generator, which is built for secrets.
How long should my password be?
Length makes the biggest difference. NIST's guidance sets a minimum of 15 characters for a password used on its own. This tool defaults to 16, and 20 or more costs you nothing if a password manager stores it.
Do I need to include symbols?
Length matters more, but each character class you add raises the entropy per character, so symbols help. Some sites reject certain symbols; if yours does, add length instead.
What does the entropy number mean?
How unpredictable the password is, in bits: length times log2 of the pool size. A 16-character password using all four sets is about 103 bits, and each extra bit doubles the work needed to guess it.
Is my password sent to your server?
No. It is generated in your browser and producing it makes no network request. It still works if you disconnect from the internet.
Do you store or log the passwords I generate?
No. No server is involved, so nothing is recorded. Once you refresh or close the page, the password is gone.
Is it safe to let a website generate my password?
It's reasonable to ask. This one runs locally with no network calls, so the password stays on your machine. To be certain, load the page, go offline, then generate.
What if I need to remember the password?
A random string is hard to memorise. Use the passphrase generator, or let a password manager remember a random one for you.
Why does the meter say 'Strong' and not 'Very strong'?
The meter checks a few things: length thresholds at 12 and 16, mixed case, a digit and a symbol. A password can have very high entropy and still sit one step below the top label. The bit count is the more precise measure.
Which characters are in the symbol set?
The symbol option adds 26 common keyboard characters: ! @ # $ % ^ and similar, plus brackets, punctuation and the less-than and greater-than signs. If a site rejects one, turn symbols off and make the password longer.
Can I generate several passwords at once?
It makes one at a time; press Generate again for another. With only one on screen, you copy the right one.

References

Every character comes from crypto.getRandomValues, the browser's cryptographically secure generator (never Math.random), and the password stays on your device.

Popular

Password Strength Checker

Check how strong a password is and get an entropy estimate in bits, plus tips on what to add. The check runs on your device and sends nothing you type.

PasswordOpen Tool
Popular

Random Number Generator

Generate random whole numbers in any range, with an option for no repeats. The numbers come from the browser's cryptographic random source, not Math.random.

PasswordOpen Tool
PopularHot

Image Compressor

Compress an image to JPEG with a quality slider and watch the file size drop as you drag, in your browser.

ImageOpen Tool
PopularHot

Merge PDF

Combine several PDFs into one file in the order you choose, without leaving your browser.

PDFOpen Tool
PopularHot

Word Counter

Count words, characters, sentences and paragraphs as you type, with reading and speaking time alongside.

TextOpen Tool
PopularHot

Meta Tag Generator

Fill in your page title, description, keywords and author, and the tool writes a block of HTML head meta tags you can paste, with the title, description, viewport and robots tags included. The block updates as you type.

SEOOpen Tool

Back to the Password Generator

Generate as many as you need at the top of the page. It runs on this device and needs no account.