// free tool - password generator

Password Generator strong, random, private

Create strong random passwords or easy-to-type passphrases in one click. See the exact entropy, avoid look-alike characters, or generate up to 500 at once. Generated on your device: nothing is logged, stored or sent.

  • Free - no sign-up
  • Runs in your browser
  • Nothing logged or sent
  • Passphrases

Generate a password

Made on your device with crypto.getRandomValues. Nothing is logged, stored or sent.

Presets
More options

Passphrase words: EFF Short Wordlist 1 by the Electronic Frontier Foundation, licensed CC BY 3.0 US. 1,296 short, easy-to-type words.

A rough estimate based on length, character types and common patterns. It cannot know whether this password already leaked in a data breach.

Bulk generate
password.txt -

    Private by design. Passwords are generated in your browser with crypto.getRandomValues, the browser's cryptographically secure random number generator. Nothing is logged, stored or sent to any server, and generated passwords are never saved in your browser. Only your settings are remembered.
    Beyond passwords

    Strong passwords are the floor. Security is the whole building.

    These AI skills plug into Claude, ChatGPT or any AI chat and help with the rest: threat reviews, secure code and training that changes how people behave.

    A password generator that never sees your password

    This free password generator creates strong random passwords and passphrases directly in your browser. It uses crypto.getRandomValues, the cryptographically secure random number generator built into every modern browser, with unbiased sampling so every character is equally likely. Nothing is logged, stored or sent: the page has no server step, and generated passwords are never saved, not even in your own browser.

    Choose the length and character types, avoid look-alike characters for passwords you have to type by hand, generate a memorable passphrase from a curated word list, or create up to 500 passwords at once for a new team or a batch of devices.

    What makes a password strong

    Strength comes from unpredictability, which is measured in bits of entropy. A password chosen at random from a pool of N characters with length L has L x log2(N) bits. Each extra bit doubles the number of guesses an attacker needs. Some reference points:

    • 8 random lowercase letters: about 38 bits. Too weak for anything important.
    • 12 random characters from letters, digits and symbols: about 78 bits.
    • 20 random characters from the same pool: about 129 bits, far beyond any realistic attack.
    • 6 words from a 1,296-word list: about 62 bits, and much easier to type and remember.

    The meter in the generator shows the exact entropy for your settings and an estimated average time to guess at 10 billion guesses per second, a rate that applies when an attacker has stolen a database of fast password hashes. Online logins are usually rate-limited, so real attacks against a login form are far slower. Treat the time as a comparison, not a promise.

    Random passwords vs passphrases

    A random string such as vT9#qL2!xR7mWc4$ packs the most entropy into the fewest characters, so it is ideal for anything stored in a password manager. A passphrase such as crane-lilac-swirl-mocha-ditch-gecko is longer but easier to read aloud, type on a phone or remember, which makes it the better choice for the few passwords you must keep in your head: your password manager, your computer login and your main email.

    The passphrase mode uses the EFF Short Wordlist 1 by the Electronic Frontier Foundation (CC BY 3.0 US): 1,296 short, distinct words chosen to be easy to spell. The words are picked by the same secure random generator, never by you, which is what makes the passphrase strong. Adding a number or symbol adds a few bits; adding one more word adds over 10.

    Practical rules that matter

    1. Use a password manager. It lets every account have a unique random password, so one leak does not unlock everything else.
    2. Prefer length over complexity. Current guidance, such as NIST SP 800-63B, focuses on length and on blocking known-compromised passwords rather than forcing symbols or regular changes.
    3. Never reuse passwords. Credential stuffing, trying leaked passwords on other sites, is one of the most common ways accounts are taken over.
    4. Turn on multi-factor authentication, ideally with an authenticator app or a hardware key, for email, banking and work accounts.
    5. Change a password when there is a reason, such as a breach notice or a shared device, rather than on a fixed schedule.

    Options explained

    Avoid look-alike characters

    Removes I l 1 | O 0 o, which are easy to confuse when you read a password from a screen or a label, for example for Wi-Fi. It slightly lowers the entropy per character, so add a character or two when you use it.

    At least one of each type

    Some sites demand a digit and a symbol. The generator meets the rule by drawing a fresh password until it contains every selected type, which keeps the result uniformly random. The entropy shown accounts for the rule exactly.

    Check strength

    The check mode gives a rough estimate for a password you already use, looking at length, character types, repeats, keyboard sequences, common passwords and word-plus-number patterns. The text stays on the page and is never stored or sent. It cannot tell whether the password has appeared in a breach, so if you reuse it anywhere, replace it.

    Security is only one part of running a team well. Browse the free AI generators and tools, or document your access rules with the README generator and test them with the test case generator.

    FAQ

    Is this password generator safe to use?

    Yes. Passwords are created in your browser with crypto.getRandomValues, a cryptographically secure random number generator. Nothing is logged, stored or sent to a server, and generated passwords are not saved in your browser.

    How long should a password be?

    Use at least 12 characters, and 16 or more for important accounts. For passwords kept in a password manager, 20 random characters is a good default. A passphrase of 6 random words is a strong, memorable alternative.

    Are passphrases as secure as random passwords?

    A passphrase of 6 words chosen at random from a 1,296-word list has about 62 bits of entropy, which is strong for most uses. Each extra word adds about 10 bits. The words must be chosen by the generator, not by you.

    What does entropy mean for a password?

    Entropy, measured in bits, describes how many guesses an attacker would need. Every extra bit doubles the work. 60 bits is strong for most accounts and 80 bits or more is very strong.

    Where does the passphrase word list come from?

    It is the EFF Short Wordlist 1 published by the Electronic Frontier Foundation under a CC BY 3.0 US license. It has 1,296 short words chosen to be easy to type and hard to confuse.