/

Password Generator

Processed Client Side

Generate strong, cryptographically-random passwords with custom rules. Uses crypto.getRandomValues for true randomness.

Configure
Length16
4128
Count
Character sets
Extra characters
Entropy103 bits
Pool: 88 chars × 16 length
Passwords (5)
Generated
1c<LY{7n2Tca^4&[)Strong
2[?c:}Jd1hlbV9:8JStrong
3N}D=>eyZ5R?,E>=BStrong
4BFDdMcZc@:@,tG]^Strong
5?6t[!qdRQ8JEoLvSStrong

Bookmark this tool now — skip the search next time you need it.

About Password Generator

This tool runs entirely in your browser. Whatever you paste is processed on your own device and is never uploaded, logged, or sent to any server.

Generate strong random passwords using the browser cryptographic random number generator. You control the length, how many to produce at once, and which character sets are in play — uppercase, lowercase, digits, symbols — plus an option to exclude ambiguous characters like 0, O, 1, l, and I for passwords that will be read aloud or typed by hand. Each password is shown with its calculated entropy in bits and a strength rating, so you can see the actual effect of adding four more characters rather than guessing. Length matters far more than complexity: a long password from a smaller alphabet beats a short one full of symbols.

Key features

  • Cryptographically secure generation via crypto.getRandomValues, never Math.random
  • Adjustable length, with entropy recalculated live as you change it
  • Four toggleable character sets — uppercase, lowercase, digits, and symbols
  • Exclude ambiguous characters (0 O 1 l I) for passwords that will be transcribed or dictated
  • Extra characters field to add your own symbols when a site restricts which ones it accepts
  • Entropy in bits plus a Weak / Fair / Good / Strong rating for every password
  • Generate a batch at once and copy them all, for provisioning several accounts in one pass
  • Runs entirely in your browser — generated passwords are never transmitted or logged anywhere

How to use it

  1. Set the length — 16 or more is a sensible default for anything that matters.
  2. Choose how many passwords to generate at once.
  3. Turn the character sets on or off, and add any extra characters the target site requires.
  4. Enable Exclude ambiguous if someone will have to read or retype the password.
  5. Click Generate, check the entropy reading, and copy the one you want or the whole batch.

Tips & common mistakes

  • Entropy is the number that matters. Aim for 75 bits or more for an important account; under about 50 bits is within reach of a determined offline attack.
  • Length beats symbol soup. Adding four characters to a password buys you far more entropy than swapping an a for an @.
  • Generate a unique password per site and store them in a password manager. Reuse is what turns one site breach into ten compromised accounts.
  • Use Exclude ambiguous for Wi-Fi keys, printed recovery codes, and anything dictated over the phone — it removes the characters people confuse.
  • If a site rejects your password, it usually bans certain symbols. Turn symbols off and add the permitted ones in the extra characters field instead of shortening the password.
  • Nothing here is sent anywhere, but the clipboard is shared with everything on your machine — paste it into your password manager promptly rather than leaving it there.
  • A generated password is only as safe as where it lands. Rotate anything you have pasted into a chat window, a ticket, or a config file committed to git.
  • Need to hash or checksum a file or string instead of generating a password? Use the Hash Generator.
  • Already have a password and just want to know how strong it is? Check it with the Password Strength Checker.

Related tools

Browse all 8 Text tools

Frequently asked questions

10

Set your desired length and character options (uppercase, lowercase, numbers, symbols), then click "Generate" — a new cryptographically random password appears instantly.

Yes — passwords are generated using crypto.getRandomValues, the browser's cryptographically secure random number generator (CSPRNG). They cannot be predicted or reproduced.

It removes characters that look similar in certain fonts: 0 and O, 1 and l and I. This reduces typing mistakes when entering passwords manually.

Entropy in bits measures how unpredictable the password is. 60+ bits is good for most accounts; 80+ bits is strong and suitable for high-value targets.

At least 16 characters with mixed character types is recommended. A 24-character password with letters and numbers is stronger than a short one with all character types.

Aim for 75 bits or more on an account that matters. Below roughly 50 bits is within reach of a determined offline attack against a leaked password database.

Yes. Adding four characters buys far more entropy than swapping an a for an @. Length is the variable that actually defeats brute force.

Turn symbols off and use the extra characters field to add only the ones that site permits. That keeps your length intact instead of shortening the password to satisfy the form.

Whenever a person has to read or retype the password — Wi-Fi keys, printed recovery codes, and anything dictated over the phone. It removes 0, O, 1, l, and I, which are easily confused.

No. They are generated in your browser with the cryptographic random source and never transmitted. Do bear in mind the clipboard is shared with everything on your machine, so paste into your password manager promptly.