A password generator that never sees your password
This free password generator creates strong random passwords and passphrases directly in your browser. It uses crypto.getRandomValues, the cryptographically secure random number generator built into every modern browser, with unbiased sampling so every character is equally likely. Nothing is logged, stored or sent: the page has no server step, and generated passwords are never saved, not even in your own browser.
Choose the length and character types, avoid look-alike characters for passwords you have to type by hand, generate a memorable passphrase from a curated word list, or create up to 500 passwords at once for a new team or a batch of devices.
What makes a password strong
Strength comes from unpredictability, which is measured in bits of entropy. A password chosen at random from a pool of N characters with length L has L x log2(N) bits. Each extra bit doubles the number of guesses an attacker needs. Some reference points:
- 8 random lowercase letters: about 38 bits. Too weak for anything important.
- 12 random characters from letters, digits and symbols: about 78 bits.
- 20 random characters from the same pool: about 129 bits, far beyond any realistic attack.
- 6 words from a 1,296-word list: about 62 bits, and much easier to type and remember.
The meter in the generator shows the exact entropy for your settings and an estimated average time to guess at 10 billion guesses per second, a rate that applies when an attacker has stolen a database of fast password hashes. Online logins are usually rate-limited, so real attacks against a login form are far slower. Treat the time as a comparison, not a promise.
Random passwords vs passphrases
A random string such as vT9#qL2!xR7mWc4$ packs the most entropy into the fewest characters, so it is ideal for anything stored in a password manager. A passphrase such as crane-lilac-swirl-mocha-ditch-gecko is longer but easier to read aloud, type on a phone or remember, which makes it the better choice for the few passwords you must keep in your head: your password manager, your computer login and your main email.
The passphrase mode uses the EFF Short Wordlist 1 by the Electronic Frontier Foundation (CC BY 3.0 US): 1,296 short, distinct words chosen to be easy to spell. The words are picked by the same secure random generator, never by you, which is what makes the passphrase strong. Adding a number or symbol adds a few bits; adding one more word adds over 10.
Practical rules that matter
- Use a password manager. It lets every account have a unique random password, so one leak does not unlock everything else.
- Prefer length over complexity. Current guidance, such as NIST SP 800-63B, focuses on length and on blocking known-compromised passwords rather than forcing symbols or regular changes.
- Never reuse passwords. Credential stuffing, trying leaked passwords on other sites, is one of the most common ways accounts are taken over.
- Turn on multi-factor authentication, ideally with an authenticator app or a hardware key, for email, banking and work accounts.
- Change a password when there is a reason, such as a breach notice or a shared device, rather than on a fixed schedule.
Options explained
Avoid look-alike characters
Removes I l 1 | O 0 o, which are easy to confuse when you read a password from a screen or a label, for example for Wi-Fi. It slightly lowers the entropy per character, so add a character or two when you use it.
At least one of each type
Some sites demand a digit and a symbol. The generator meets the rule by drawing a fresh password until it contains every selected type, which keeps the result uniformly random. The entropy shown accounts for the rule exactly.
Check strength
The check mode gives a rough estimate for a password you already use, looking at length, character types, repeats, keyboard sequences, common passwords and word-plus-number patterns. The text stays on the page and is never stored or sent. It cannot tell whether the password has appeared in a breach, so if you reuse it anywhere, replace it.
Security is only one part of running a team well. Browse the free AI generators and tools, or document your access rules with the README generator and test them with the test case generator.
FAQ
Is this password generator safe to use?
Yes. Passwords are created in your browser with crypto.getRandomValues, a cryptographically secure random number generator. Nothing is logged, stored or sent to a server, and generated passwords are not saved in your browser.
How long should a password be?
Use at least 12 characters, and 16 or more for important accounts. For passwords kept in a password manager, 20 random characters is a good default. A passphrase of 6 random words is a strong, memorable alternative.
Are passphrases as secure as random passwords?
A passphrase of 6 words chosen at random from a 1,296-word list has about 62 bits of entropy, which is strong for most uses. Each extra word adds about 10 bits. The words must be chosen by the generator, not by you.
What does entropy mean for a password?
Entropy, measured in bits, describes how many guesses an attacker would need. Every extra bit doubles the work. 60 bits is strong for most accounts and 80 bits or more is very strong.
Where does the passphrase word list come from?
It is the EFF Short Wordlist 1 published by the Electronic Frontier Foundation under a CC BY 3.0 US license. It has 1,296 short words chosen to be easy to type and hard to confuse.