Skip to main content

Password Generator

Generate strong random passwords in your browser using crypto.getRandomValues. Choose length, character sets and how many to produce, with an entropy readout.

Produce random passwords of the length and character composition you choose, generated by the browser's cryptographic random number source. Several can be generated at once, and the entropy figure tells you how much real strength the settings give you.

Password Generator
VERY STRONG
BG$s(%0HQsZ8kKUM

Uses crypto.getRandomValues() · generated entirely in your browser

// Password Generator: Features

The randomness matters more than the rules

Passwords are generated with crypto.getRandomValues, the browser's cryptographically secure random source, rather than Math.random. The distinction is not academic: Math.random is designed to be fast and statistically even, not unpredictable, and its output can be reconstructed from a handful of previous values. For anything that protects an account, the generator has to be one an attacker cannot predict, and that is what the Web Crypto source provides.

Length beats complexity

The entropy figure makes the trade-off concrete. Adding a character set multiplies the size of the pool once; adding a character multiplies the number of possibilities by the whole pool size. A sixteen-character password of lower-case letters alone is stronger than a nine-character password using every symbol on the keyboard. The composition rules that many sites impose are largely a historical artefact, and length is where real strength comes from.

Reading the entropy number

Entropy in bits measures how many equally likely possibilities an attacker must search. Each additional bit doubles that number. Below about sixty bits a password is within reach of a determined offline attack on stolen hashes; eighty bits is comfortable for most purposes; above a hundred is beyond any foreseeable brute force. The figure assumes the password is genuinely random, which is true here and is not true of anything a person invents.

Generating several at once

Producing a batch is useful when you are setting up several accounts or services in one sitting, or when you want to pick one that is easier to type or read aloud. Copy all takes the whole list. Bear in mind that the more places a generated password is copied through, the more places it can be left behind: a clipboard manager, a terminal history, a chat message.

Nothing is stored, so copy before you reload

Generation happens entirely in your browser. The passwords are never sent anywhere, never stored and never logged, and there is no history: reloading the page discards them. That is what makes a browser-based generator reasonable for real credentials, where an online service that generates on a server is not. The best destination for whatever you generate is a password manager, which removes the need to see or remember it again.

// Password Generator: FAQ

How random are these passwords?

They are generated with crypto.getRandomValues, the browser's cryptographically secure random number generator, which is the same primitive used for key generation elsewhere. This is deliberately not Math.random, whose output is predictable from previous values and unsuitable for anything security-related.

How long should a password be?

Sixteen characters is a sound default for an account you care about, and twenty or more for anything high-value such as a password manager master password or a root credential. Length contributes far more to strength than character variety, so prefer a longer password from a smaller alphabet over a short one full of symbols.

What does the entropy figure mean?

It is the number of bits of randomness, where each bit doubles the search space an attacker faces. As a rough guide, under sixty bits is weak against offline attacks on a stolen hash database, around eighty is comfortable, and over a hundred is beyond brute force for the foreseeable future.

Should I include symbols?

They help, but less than adding characters does. Some systems also reject particular symbols or handle them badly, which is a practical reason to leave them out and add length instead. If a site rejects your password without explanation, an unusual symbol is a likely culprit.

Is it safe to generate a password on a website?

It depends entirely on where the generation happens. Here it happens in your browser: nothing is transmitted, stored or logged, and you can confirm that in the network tab of your developer tools. A generator that produces the password on a server is a different proposition, because the value exists somewhere you do not control.

Are the passwords stored or recoverable?

No. There is no history and nothing is written anywhere. Reloading the page or closing the tab discards them permanently, so copy a password into your password manager before navigating away.

Why generate more than one at a time?

Convenience when you are setting up several accounts in one session, and choice when you want one that is easier to read or type. Be aware that every extra copy is another place the value can linger, so generate what you need rather than a long list.

Are random passwords better than passphrases?

For anything stored in a password manager, a random string is ideal because you never type it. For the handful you must type from memory, such as a manager master password or a device login, a long passphrase of unrelated words is easier to remember at equivalent strength. Use the right form for each job.

Can I generate passwords offline?

Yes, once the page has loaded. Generation uses only browser APIs, so it continues to work with the network disconnected, which is one way to satisfy yourself that nothing is being transmitted.

What should I do with the password after generating it?

Put it straight into a password manager. Reusing passwords across sites is the single largest practical risk, and a manager removes both the reuse and the need to remember anything. Avoid sending a generated password through chat or email, where it persists in places you cannot clean up.

// How to Use Password Generator

  1. Set the length

    Choose how long the password should be. Sixteen characters is a sensible default; go longer for anything protecting other credentials, such as a password manager master password.

  2. Choose the character sets

    Enable lower case, upper case, digits and symbols as required. At least one set must be selected. If a site rejects the result, an unusual symbol is the most likely reason, so try again without them and add length instead.

  3. Generate and store it

    Generate one password or a batch, then copy it straight into your password manager. Nothing is kept here, so reloading the page discards the result permanently.

Category Security