Password Generator
Create strong random passwords, easy-to-remember passphrases and safe PINs in one click. Every password is generated on your device with cryptographic randomness and never leaves it.
At a glance
- Uses the browser’s Web Crypto API (
crypto.getRandomValues) with rejection sampling, so every character is uniformly random with no modulo bias. - Three modes: random passwords (4–128 characters), passphrases from the EFF short word list, and numeric PINs (4–12 digits).
- Options to include or exclude uppercase, lowercase, numbers and symbols, skip look-alike characters (I, l, 1, O, 0) and ban any custom characters.
- Shows strength as bits of entropy and an estimated time to crack at 100 billion guesses per second.
- Generates up to 100 passwords at once, with copy-all and download as a .txt file.
- Passwords are created on your device and are never sent, logged or stored.
- Obvious PINs such as 1111, 1234 and 1212 are never produced.
Step by step
How to generate a strong password
- 1
Choose a type
Select Password, Passphrase or PIN at the top of the options.
- 2
Set the length and characters
Use at least 16 characters with all four character types for a password, or 5+ words for a passphrase.
- 3
Check the strength
Aim for Strong or Very strong — at least 60–80 bits of entropy for important accounts.
- 4
Copy and save it
Click Copy, paste the password into the website, and store it in a password manager. Click the refresh button for a new one.
Features
Everything you need, nothing you don’t
Truly random
Built on crypto.getRandomValues, the same cryptographically secure source browsers use for encryption keys — not the predictable Math.random.
Passwords, passphrases and PINs
Pick a random password for maximum strength, a word-based passphrase you can actually remember, or a numeric PIN for cards and phones.
Honest strength meter
Strength is calculated from real entropy (bits) and turned into an estimated cracking time, so you can see exactly how much length and variety matter.
Fits any site’s rules
Choose character types, guarantee at least one of each, avoid look-alike characters and exclude symbols a website refuses.
Easy to read back
Numbers and symbols are colour-coded so you can type a password on another device without mistakes.
Bulk generation
Create up to 100 passwords in one go for new accounts, Wi-Fi guests or test users, then copy or download them all.
What makes a password strong?
Strength comes from unpredictability, measured in bits of entropy. Every extra bit doubles the number of guesses an attacker needs. A password drawn at random from 87 possible characters gains about 6.4 bits per character, so length matters more than anything else: 16 random characters give roughly 103 bits, far beyond the reach of any known attack.
Human-chosen passwords are weak even when they look complex, because attackers try dictionary words, names, dates and common substitutions like “P@ssw0rd” first. A generator removes that pattern entirely — which is why you should never tweak a generated password to make it “more memorable”.
- *Offline attack at 100 billion guesses per second against a fast hash. Websites that store passwords properly (bcrypt, scrypt, Argon2) and limit login attempts make real-world attacks far slower.
| Password | Entropy | Average time to crack* |
|---|---|---|
| 8 random characters (all types) | ~52 bits | about 5 hours |
| 12 random characters (all types) | ~77 bits | about 30,000 years |
| 16 random characters (all types) | ~103 bits | trillions of years |
| 5-word passphrase + number | ~57 bits | about 11 days |
| 7-word passphrase | ~72 bits | about 1,000 years |
| 6-digit PIN | ~20 bits | less than a second (offline) |
Password or passphrase?
Use a random password for anything stored in a password manager — you never need to remember it, so make it long. Use a passphrase for the few secrets you must type from memory: your password manager’s master password, your computer login, or a Wi-Fi password guests will type. Six or seven random words are both strong and surprisingly easy to remember.
Passphrases here use the Electronic Frontier Foundation’s short word list of 1,296 common, easy-to-spell words, giving about 10.3 bits of entropy per word.
Password best practices
- Use a unique password for every account. When one site is breached, reused passwords are tried everywhere else within hours.
- Use a password manager to store them — Bitwarden, 1Password, KeePass, or the one built into your browser or phone.
- Turn on two-factor authentication (an authenticator app or passkey) for email, banking and social accounts.
- Don’t change strong passwords on a schedule. Change a password when there is a reason: a breach, a shared device, or a suspicion.
- Never send passwords by email or chat. Share them through your password manager’s sharing feature instead.
Is it safe to generate passwords online?
It is when the generator runs entirely in your browser, as this one does. The page uses your device’s cryptographic random number generator; the passwords are never transmitted, logged or saved, and they disappear when you close the tab. You can confirm it yourself: load the page, disconnect from the internet and keep generating.
FAQ
Frequently asked questions
Is this password generator safe?
How long should my password be?
Are symbols really necessary?
Why are some symbols left out?
What does “bits of entropy” mean?
How is the time to crack estimated?
Can I generate many passwords at once?
Is a passphrase as secure as a random password?
Keep going
Related tools
SSL Checker
Check any website’s SSL certificate: expiry date and days left, issuer, covered domains, revocation and CAA, plus a live HTTPS test from your browser.
Image Steganography Tool
Hide a secret message or file inside an image, protected with a password, and reveal hidden messages from PNG images. Free and private — no upload.
Password Strength Checker
Check how strong a password is: time to crack, common words and patterns it hides, tips to improve it, and a safe data-breach check. Fully private.
PPK to PEM Converter
Convert a PuTTY .ppk private key to PEM or OpenSSH format online, with or without a passphrase. Supports PPK v2 and v3, RSA, ECDSA and Ed25519. No upload.
PEM to PPK Converter
Convert a PEM or OpenSSH private key (id_rsa, AWS .pem) to a PuTTY .ppk file online — PPK v3 or v2, with an optional passphrase. Free, private, no upload.
Bcrypt Generator & Checker
Generate bcrypt hashes with cost 4–16 and $2a/$2b/$2y prefixes, or check a password against a bcrypt hash. Explains each part. Runs in your browser only.
Last updated Report a problem or suggest a feature