Password Generator
Generate strong, random passwords right in your browser — nothing is sent anywhere.
How to use
- Choose a length with the slider.
- Toggle uppercase, numbers and symbols.
- Click Generate, then click the password to copy it.
How the Password Generator works
Generates strong random passwords in your browser using the operating system's cryptographic random number source, with control over length and character set.
Characters are drawn from the selected pools — lowercase always, plus optional uppercase, digits and symbols — using crypto.getRandomValues rather than Math.random. That distinction matters: Math.random is predictable and unfit for anything security-related.
entropy (bits) = length × log₂(character pool size)
Worked example
A 16-character password from all four pools draws on 94 possible characters, giving 16 × log₂(94) ≈ 105 bits of entropy — far beyond brute-force reach.
Things worth knowing
- Length beats complexity. A 20-character lowercase-only password has more entropy than a 10-character password using every symbol.
- Nothing is transmitted. The password is generated locally and never leaves your device.
- A unique password per site is the point. Reuse is what turns one site's breach into a compromise of all your accounts — use a password manager.
Frequently asked questions
Are these passwords safe to use?
Yes — they're generated locally using your browser's cryptographic random source and never leave your device.
How long should a password be?
Aim for at least 16 characters with a mix of character types for strong security.
Are random passwords better than passphrases?
Both work if long enough. A four-or-five-word random passphrase is easier to type and remember; a random string is denser per character.
Is generating a password in a browser safe?
Here, yes — generation is local and uses the platform's cryptographic RNG. The risk with such tools is transmission, and nothing is transmitted.