Strong Password Generator

Generate passwords from the browser's own randomness, with the entropy in bits stated: the only honest measure of how strong a random password is.

Enable JavaScript to customise; default output below.

Length beats complexity. Twenty characters is comfortably past brute force.

More options Show
Live preview passwords.txt
# 20 characters from 86 possible, 128.5 bits of entropy: strong: no practical brute force
generated-in-your-browser

Output is valid and updates as you type.

Generate random passwords in your browser, and see the entropy in bits rather than a colour bar.

How to use

  1. Set the length. Length is what makes a random password strong; twenty characters is comfortably past any brute force.
  2. Choose the character sets. Each one you add raises the entropy per character a little; length raises it a lot.
  3. Turn on “avoid lookalike characters” for a password someone will read off a screen and type on a phone.
  4. Read the entropy line. It says how many bits of randomness the password has, and what that means for offline guessing.
  5. Copy the one you want. Values are generated in your tab and nothing is uploaded or stored.

Example

# 20 characters from 86 possible, 128.5 bits of entropy: strong: no practical brute force
n7$Kq2wV!pRz4mHc9Tb@

Twenty characters from the full set is about 129 bits. Dropping symbols takes it to 119, and dropping to lowercase only takes it to 94: still far beyond brute force, which is the point. Length dominates.

Pitfalls

  • A strength meter is a guess. Entropy is arithmetic: the alphabet size to the power of the length, expressed in bits. That is what is shown here.
  • Entropy only describes a random password. Summer2026! has about 40 bits by that formula and about 10 in reality, because it follows a pattern a cracker tries first.
  • Forced complexity rules push people towards patterns. P@ssw0rd1 satisfies most of them; a long random string satisfies them accidentally.
  • Symbols are the first thing a system rejects. A password manager hides that pain; a login form that silently truncates does not.
  • A truncating system is worse than a short limit. If a field accepts 72 characters and keeps 20, the extra length bought nothing.
  • Reuse beats every strength calculation. A 129-bit password used on two sites is as strong as the weaker site’s database.
  • Browser randomness is the right source here. A password from Math.random() is predictable from a few samples, which is why this uses the cryptographic generator.
  • Writing a generated password into a chat message or a ticket puts it in a log. Use a password manager’s share feature instead.

Compatibility

Randomness comes from crypto.getRandomValues, available in every browser since 2014. Selection uses rejection sampling, so each character is equally likely; taking a random byte modulo the alphabet size, which is the common shortcut, makes the first few characters slightly more likely and quietly costs a fraction of a bit. The server-rendered default is a placeholder, never a real password, so no two visitors are given the same one.

Frequently asked questions

How long should a password be?
Sixteen characters is fine, twenty is comfortable, and more than thirty only matters for a key. Length before complexity.
What is a bit of entropy?
One bit doubles the number of guesses needed. Sixty bits is about a billion billion guesses, which is hours on rented hardware for a fast hash and centuries for a slow one.
Are the passwords stored or sent anywhere?
No. They are generated in this tab, and the page holds nothing.
Should I use a passphrase instead?
Four or five random words is comparable entropy and far easier to type. This tool makes character passwords; either is fine if the words are chosen randomly.
Why does the entropy change when I turn off symbols?
Because the alphabet shrank. Sixty-two characters gives 5.95 bits each, eighty-six gives 6.43.
Weekly drops

New tools, when there are new tools

One email when something worth using ships. No schedule to fill, so no filler.

Your address goes nowhere else, and one click unsubscribes.