Strong Password Generator

Create a strong random password in one click. Choose the length and characters, and see how strong it is. Everything happens in your browser.

Passwords are generated in your browser with the Web Crypto API. Nothing is sent to our server or stored.

How it works

The generator uses crypto.getRandomValues(), the browser’s cryptographically secure random number source, with unbiased sampling, so every character is equally likely. It guarantees at least one character from every type you select, then shuffles the result. Nothing is sent to our server, logged or stored.

Options

What the strength meter means

Strength is shown as entropy in bits: length × log₂(size of the character set). Each extra bit doubles the number of guesses an attacker needs.

EntropyRatingExample
Under 40 bitsWeak6 lowercase letters
40–60 bitsFair10 letters and digits
60–80 bitsStrong12 characters, all types
80+ bitsVery strong16+ characters, all types

This assumes the password is truly random, which it is here. Human-chosen passwords are much weaker than their length suggests.

Password habits that matter most

  1. Use a different password for every account. Reused passwords are how one breach becomes many.
  2. Use a password manager to store them, so you only remember one strong master password.
  3. Turn on two-factor authentication, ideally with an authenticator app or passkey.
  4. Change passwords after a breach, not on a fixed schedule.

Frequently asked questions

Is it safe to generate a password on a website?

This generator runs entirely in your browser using the Web Crypto API's cryptographically secure random numbers. The password is never sent over the network or saved. You can even load the page and then go offline to generate one.

How long should my password be?

For accounts protected by a password manager, 16–20 random characters is plenty. For a password you must type by hand, a longer passphrase of random words is easier to remember and type.

Last updated

Related tests