What it does
The password generator creates strong, random passwords from the character sets you choose: lowercase letters, uppercase letters, digits and symbols. Each password is guaranteed to contain at least one character from every set you turn on, which satisfies the composition rules most websites enforce.
Randomness comes from your browser’s cryptographically secure generator, not from Math.random. Characters are chosen with rejection sampling, so every character in the pool is equally likely and there is no bias toward the start of the alphabet.
How to use
- Pick a Length. The label shows the entropy of one password with the current settings.
- Pick How many passwords to generate at once.
- Turn character sets on or off. Turn on Avoid look-alikes if the password will be read or typed by hand.
- Click Generate for a fresh batch, then copy a line or download the list.
What makes a password strong
Length matters more than complexity. A 16-character password using all 94 printable ASCII characters has about 104 bits of entropy; even at a trillion guesses per second, trying every combination would take far longer than the age of the universe. A short password with symbols is weaker than a long one with only letters.
Equally important: use a different password for every site, and keep them in a password manager. Most account takeovers come from passwords reused after another site was breached, not from guessing.
Example
With the default settings (16 characters, all sets), you get passwords like:
q7#Lm2^vR!xP9tGd
Wz$4kN8@hE&c3uJy
Each one is different every time; these examples are for illustration only, so do not use them.
FAQ
› Are the passwords generated on a server?
No. They are created in your browser with the Web Crypto API (crypto.getRandomValues), a cryptographically secure random generator. Nothing is sent over the network or stored.
› How long should my password be?
For accounts protected by a password manager, 16 or more characters from all four sets is plenty (over 100 bits of entropy). For a master password or disk encryption key, use 20 or more.
› What does "bits of entropy" mean?
It measures how many guesses an attacker would need: each extra bit doubles the work. It is calculated as length × log2(number of possible characters). 80 bits is strong against online and most offline attacks; 100+ bits is beyond any practical brute force.
› Why avoid look-alike characters?
Characters such as 0 and O, or 1, l and I, are hard to tell apart when you read a password aloud or type it from paper. Excluding them costs a little entropy, which you can make up with a slightly longer password.