Free & unlimited

Password Generator

Generate a strong, random password using a secure random source.

16 characters

What this tool does

Generates a random password using your browser's cryptographically secure random number generator (crypto.getRandomValues) — the same class of randomness used for encryption keys, not a predictable Math.random() function.

The password is generated on your device and never transmitted or stored anywhere.

How to use this tool

1Set the length — 16 or more characters is a sensible floor for an account that matters.
2Choose which character types to include: uppercase, lowercase, numbers, symbols.
3Turn on "exclude ambiguous" if you'll be typing the password by hand from a printout.
4Click Generate, check the strength label, then Copy and paste it straight into your password manager.

What actually makes a password strong

Resistance to guessing comes overwhelmingly from length and randomness, not from cramming in symbols. Each extra random character multiplies the number of possibilities an attacker has to try:

  • A random 16-character password using letters, numbers, and symbols is far beyond any practical brute-force attack.
  • A 20+ character passphrase of unrelated words can be just as strong and much easier to type — useful for the handful of passwords you can't store in a manager (your device login, the manager's own master password).
  • Predictable substitutions like P@ssw0rd add almost nothing — attackers try those first.

Current NIST guidance drops forced complexity and periodic resets in favour of longer passwords and checking them against known-breached lists. The one rule that always holds: never reuse a password across sites.

FAQ

How long should my password be?
At least 16 characters for anything important. Go longer for high-value accounts (email, banking, your password manager). Below about 12 characters, a random password is no longer comfortably out of reach.
Why exclude ambiguous characters?
Characters like I, l, 1, O, and 0 look identical in some fonts. Excluding them matters only if you'll type the password manually from a printout — if you're pasting from a manager, leave them in for a slightly larger character pool.
How is the strength label calculated?
From entropy — the password length multiplied by the log2 of your character-pool size. It estimates how many guesses a brute-force attack needs. It does not check whether the exact password has appeared in a data breach.
Where should I store the generated password?
In a password manager. Generating a strong unique password per site only helps if you're not trying to remember them — the manager fills them for you and flags reused or breached ones.
Is the password sent to a server or logged?
No. Generation happens entirely in your browser. Nothing is transmitted, and nothing is stored once you leave the page — reload and the previous password is gone.