Password Generator
Create genuinely strong passwords with the exact length and character sets each site demands. Generation uses cryptographic randomness on your device — nothing is transmitted or logged.
How it works
Set the length, tick the character sets you want (lowercase, UPPER, digits, symbols) and hit Generate. Each character is drawn with crypto.getRandomValues, and you can copy the result in one click.
Formula and source
Strength ? length × log2(pool size) bits of Shannon entropy — e.g. 16 characters from all 94 printable ASCII symbols ? 104.9 bits. Last verified 2026-10-09.
Worked examples
- 16 characters, all sets on ? ?104.9 bits of entropy — far beyond brute force
- 12 lowercase-only characters ? ?56.4 bits — fine for low-value accounts, weak for email/banking
Common mistakes
- Reusing one strong password everywhere defeats its strength — use a manager.
- Disabling symbols to satisfy a broken site and then reusing that weaker password elsewhere.
- Trusting "pronounceable" or pattern-based passwords for high-value accounts without enough length.
Tips
- 16+ characters with all sets for email, banking and password managers.
- Check strength claims with the Password Entropy tool on this site.
FAQ
What makes a password strong?
Length plus unpredictability: long, random, and unique per site beats clever patterns.
How long should passwords be?
16+ random characters for important accounts; 20+ for your password manager itself.
Are generated passwords truly random?
Yes u2014 this tool uses your browser’s cryptographic RNG, not Math.random.
Should I use symbols?
They enlarge the pool, but extra length helps more; use both when allowed.
Is the password generator free?
Yes, completely free with no signup.
Do you see or store my passwords?
No u2014 generation and display never leave your device.