Password Generator
Generate passwords from crypto.getRandomValues with control over length and character sets, and an entropy estimate.
Runs in your browser — nothing is uploadedFree trial: 1 run of Password Generator every day. After that, 2 credits per run.
Generate a random password and see the entropy behind it
Choose a length between 8 and 64 characters and which sets to draw from — lowercase, uppercase, digits and symbols. Characters come from the browser's cryptographic random number generator using rejection sampling, so no character is more likely than another. The entropy in bits is shown alongside, so the strength figure is something you can check rather than a coloured bar.
What Password Generator gives you
Length from 8 to 64
A slider covering everything from a minimum-length field to a long passphrase-grade string.
Four character sets
Lowercase, uppercase, digits and symbols, each switched on or off independently.
Exclude look-alike characters
Drop l, I, 1, O, 0 and o when the password will be read aloud, copied by hand or typed from a printout.
Entropy in bits, not a vague rating
The figure is the base-2 logarithm of how many passwords your settings allow, with a plain-language label beside it.
Generated locally and never stored
The password is produced in your browser, is not sent anywhere, and is discarded when you navigate away.
How to use Password Generator
Set the length
Longer is stronger; the entropy figure updates as you move the slider.
Choose character sets
At least one must be selected. More sets mean a larger alphabet and more entropy per character.
Exclude look-alikes if needed
Useful when a person rather than a password manager will be typing it.
Copy it
Paste it straight into your password manager.
Other names for this tool
People also look for this as random password generator, strong password creator, secure password maker, passphrase generator and create a password online. It is the same tool on this page.
Limitations
- Passwords are never persisted, so navigating away discards them.
Questions about Password Generator
Where does the randomness come from?
crypto.getRandomValues, with rejection sampling so no character is more likely than another. Math.random is never used.
Is the password stored or sent anywhere?
No. It is generated in the page and never transmitted, logged, placed in the URL or stored by default.
How long should a strong password be?
Length buys more strength than exotic characters. Going from 12 to 20 characters helps far more than adding punctuation to a short one. Aim for at least 80 bits of entropy, which the page shows as you adjust the settings.
Is this password generator actually random?
It draws from the platform cryptographic random source rather than the ordinary pseudo-random function, and uses rejection sampling so no character is more likely to appear than another. That second part matters — naive generators quietly bias the alphabet.
What does entropy in bits actually mean?
It is the base-2 logarithm of how many different passwords your chosen length and character sets allow. Each extra bit doubles the number of guesses needed, which is why the figure is a far better guide than a colour-coded strength bar.
Is my generated password sent anywhere or saved?
No. It is produced in your browser, never transmitted, and never written to storage — navigating away discards it. Copy it into a password manager immediately, because nothing here will remember it for you.
Why would I exclude look-alike characters?
Because l, I and 1 are easy to confuse, as are O, 0 and o. Turn the option on whenever a person will read the password aloud, copy it from a printout or type it on a device without a password manager.
What if a site rejects symbols in passwords?
Switch the symbol set off and add length to compensate. A longer password drawn from a smaller alphabet can easily carry more entropy than a short one with punctuation in it.