Strong Password Generator
Generate passwords from the browser's own randomness, with the entropy in bits stated: the only honest measure of how strong a random password is.
# 20 characters from 86 possible, 128.5 bits of entropy: strong: no practical brute force
generated-in-your-browser
Output is valid and updates as you type.
Fix the highlighted fields to update the output.
Generate random passwords in your browser, and see the entropy in bits rather than a colour bar.
How to use
- Set the length. Length is what makes a random password strong; twenty characters is comfortably past any brute force.
- Choose the character sets. Each one you add raises the entropy per character a little; length raises it a lot.
- Turn on “avoid lookalike characters” for a password someone will read off a screen and type on a phone.
- Read the entropy line. It says how many bits of randomness the password has, and what that means for offline guessing.
- Copy the one you want. Values are generated in your tab and nothing is uploaded or stored.
Example
# 20 characters from 86 possible, 128.5 bits of entropy: strong: no practical brute force
n7$Kq2wV!pRz4mHc9Tb@
Twenty characters from the full set is about 129 bits. Dropping symbols takes it to 119, and dropping to lowercase only takes it to 94: still far beyond brute force, which is the point. Length dominates.
Pitfalls
- A strength meter is a guess. Entropy is arithmetic: the alphabet size to the power of the length, expressed in bits. That is what is shown here.
- Entropy only describes a random password.
Summer2026!has about 40 bits by that formula and about 10 in reality, because it follows a pattern a cracker tries first. - Forced complexity rules push people towards patterns.
P@ssw0rd1satisfies most of them; a long random string satisfies them accidentally. - Symbols are the first thing a system rejects. A password manager hides that pain; a login form that silently truncates does not.
- A truncating system is worse than a short limit. If a field accepts 72 characters and keeps 20, the extra length bought nothing.
- Reuse beats every strength calculation. A 129-bit password used on two sites is as strong as the weaker site’s database.
- Browser randomness is the right source here. A password from
Math.random()is predictable from a few samples, which is why this uses the cryptographic generator. - Writing a generated password into a chat message or a ticket puts it in a log. Use a password manager’s share feature instead.
Compatibility
Randomness comes from crypto.getRandomValues, available in every browser since 2014. Selection uses rejection sampling, so each character is equally likely; taking a random byte modulo the alphabet size, which is the common shortcut, makes the first few characters slightly more likely and quietly costs a fraction of a bit. The server-rendered default is a placeholder, never a real password, so no two visitors are given the same one.