Password Generator

Generate strong, random passwords instantly. Customize length and character sets. Cryptographically secure. Free, browser-based, no password stored or transmitted.

  • Runs in your browser
  • Your data never leaves your browser
  • Free · No Sign-Up

Generated passwords appear here.

Click Generate
Read the full guide How to Create a Strong Password: Length, Randomness and the NIST Rules
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.

How the Strength Number Is Calculated

The meter does not guess how “complex” a password looks. Because every character is drawn uniformly from the selected set, the number of possible passwords is set size raised to length, and the entropy in bits is length × log2(set size). The labels are fixed bands: under 40 bits Very Weak, 40–59 Weak, 60–79 Fair, 80–99 Strong, 100 and above Very Strong.

SettingsSet sizeLengthMeter
All four sets (default)8820Very Strong (129 bits)
All four sets, exclude ambiguous8316Very Strong (102 bits)
Upper + lower + digits6214Strong (83 bits)
Lowercase + digits3612Fair (62 bits)
All four sets888Weak (52 bits)

The table shows why length matters more than adding a set: going from 62 to 88 characters adds about 0.5 bits per character, while one extra character from the 62-character set adds about 6 bits.

Example Output

One run with the default settings (all four sets, 20 characters) printed:

_Q;.Q{4(W$WiO=@^[@O! — Very Strong (129 bits)

With Exclude ambiguous on and length 16 it printed p#mzk<#nEyeXu#UU (Very Strong (102 bits)), and with only lowercase and digits at length 12 it printed gbkh5k0nlo2r (Fair (62 bits)). Your results will differ on every click; that is the point.

Notice the first example repeats @, Q and O. Repeats are normal in a random string and do not lower the entropy; a generator that avoided them would actually have fewer possible outputs.

Limits

  • Length 4 to 128. Values outside the range are clamped to 4 or 128; 0 or an empty field gives 20. NIST SP 800-63B asks sites to accept at least 64 characters, but many still cap length lower; check before pasting a 128-character password.
  • No “one of each” guarantee. Characters are drawn independently, so a password can lack a digit or a symbol. With all four sets, a 20-character password has no digit about 9% of the time and a 12-character one about 24% of the time. Sites that enforce such rules will reject it; generate again.
  • Fixed symbol list. 26 ASCII symbols are used; " ' / \ ` ~ and space are never included, and there is no field for a custom set or for removing single symbols.
  • No passphrases. The tool makes character passwords only, not word-list passphrases (Diceware-style).
  • bcrypt truncates. If the password will be hashed with bcrypt, only the first 72 bytes count; a 128-character password gives no extra protection there. To produce a bcrypt hash, use the bcrypt generator.
  • Nothing is kept. The tool writes no result to storage, so the passwords are gone once you close the tab. Copy the password into a password manager before leaving.

What the Standards Say About Password Rules

NIST SP 800-63B requires at least 15 characters for a password used as a single factor (8 when it is part of multi-factor login), says services should accept all printing ASCII characters and spaces, and forbids composition rules such as “must contain a symbol” and forced periodic changes. A long, random password from this page satisfies any length rule; the symbol option exists mainly for older sites that still demand one.

Password Security Tips

  • Use a unique password for every account. A password manager makes this practical.
  • Enable two-factor authentication wherever possible, regardless of password strength. The TOTP generator shows how authenticator codes are derived.
  • Never use personal information (birthdays, names) in passwords — even partially.

FAQ

Are generated passwords stored anywhere?

No. Passwords are generated in your browser with the Web Crypto API and are never sent to a server or written to storage. This page also does not load Google Analytics or AdSense. Close the tab and they're gone.

Is this cryptographically secure?

Yes. Each character comes from window.crypto.getRandomValues(), the browser's cryptographically secure random source. A 32-bit value that would make some characters slightly more likely (modulo bias) is discarded and drawn again, so every character in the selected set has the same probability.

What password length should I use?

NIST SP 800-63B requires at least 15 characters for a password that is the only factor and at least 8 when it is one part of multi-factor login. With the default 88-character set, 16 characters give about 103 bits and 20 characters about 129 bits; a password manager makes the length free to use.

Why did a site reject the password for missing a digit or symbol?

The generator picks every character independently from the selected sets; it does not force one character from each set. With all four sets and 20 characters, about 9% of passwords have no digit. Click Generate again, or use a longer length.

Which symbols are included?

26 symbols: ! @ # $ % ^ & * ( ) - _ = + [ ] { } | ; : , . < > ?. Quotes, backslash, slash, backtick, tilde and space are never used, which avoids escaping problems in shell commands, JSON and config files.