Password Generator

Create strong, random passwords. Choose the length and character types; see how strong your password is with an instant strength meter.

Runs 100% in your browser — the password you generate is never sent anywhere or saved.
Your password will appear here after you click Generate…

Why Is a Strong Password So Important?

Weak passwords (a name, a birth date, "123456", sequential keyboard patterns) can be cracked in seconds by brute-force or dictionary attacks; a large share of known data breaches also trace back to weak or reused passwords. This tool generates a password that is completely random and doesn't depend on human memory or habits — drawn from the uppercase, lowercase, digit and symbol character sets you choose, relying on your browser's cryptographically secure random number generator (see the FAQ below).

When to use it: when creating a new account, when generating a strong master password to save in a password manager (1Password, Bitwarden, etc.), or whenever you need a random string for your Wi-Fi network or an API key. You can adjust the length slider and character type checkboxes to match your target platform's rules — for example, some legacy systems restrict symbol usage, in which case selecting only letters and digits and increasing the length (e.g. 20+ characters) can maintain a similar level of security.

Practical tip: generate a separate password for each account and store it in a password manager — reusing the same password in multiple places puts all of your accounts at risk from a single breach. This tool never saves the password it generates anywhere; the password you see on screen is permanently lost when you refresh or close the page, so save it somewhere secure right after copying it.

The effect of character-type variety is bigger than you might think: an 8-character password made only of lowercase letters has 26⁸ (~208 billion) possible combinations, while a password of the same length using the full mix of uppercase, lowercase, digits, and this tool's symbol set (28 symbols) draws from a 90-character pool, jumping to 90⁸ (~4.3 quadrillion) combinations. The leap from "Weak" to "Very Strong" on the strength meter comes from exactly this difference — increasing length alone isn't enough; widening the character pool matters just as much.

Try This Next

Finished here? These might be your next step.

Frequently Asked Questions

Entropy is a measure, in bits, of how "unpredictable" a password is, computed roughly as length × log2(character pool size). Every extra bit doubles the number of possible combinations; so as both length and the variety of character types used (uppercase/lowercase, digits, symbols) increase, brute-forcing the password becomes exponentially harder. The strength indicator on this tool is based on exactly this calculation.

Math.random() was not designed for cryptographic security — the algorithms most browsers use internally (e.g. xorshift128+) can become predictable through reverse engineering once enough output has been observed. That's an unacceptable risk when generating something as security-critical as a password. crypto.getRandomValues(), on the other hand, relies on the operating system's cryptographically secure random number generator (CSPRNG) and is the method browsers recommend for this kind of use — this tool generates every character of the password with it, using an unbiased selection algorithm.

No. The password is generated entirely in your browser, in your device's memory; it's never sent to a server, never written to localStorage/sessionStorage, and never sent to analytics tools. If you refresh or close the page, the password you were looking at is permanently lost — so it's recommended to copy the generated password and save it directly to a password manager or the relevant account.

By today's standards, for most accounts a password of at least 12–16 characters that includes every character type (uppercase/lowercase, digits, symbols) strikes a good balance — longer is always safer. Using a separate, unique password for each account, and enabling two-factor authentication (2FA) wherever possible, prevents a single leaked password from affecting your other accounts.

Yes — the generation method (CSPRNG via crypto.getRandomValues) is secure enough for critical accounts too. Security after generation is in your hands: save the password in a trusted password manager, don't share it over email or messaging, and enable two-factor authentication (2FA) on the account if possible.

Copying uses the browser's standard clipboard API; the password can remain on the clipboard until you copy something else or restart your device. If you're on a shared computer, it's good practice to clear the clipboard (e.g. by copying some other text) right after pasting the password where it's needed.

Last updated: