About the Password Generator
This password generator creates strong random passwords right in your browser using the Web Crypto API — the same cryptographically secure randomness used by password managers. Nothing is sent to a server or stored, so the password you see exists only on your screen until you copy it.
Choose the length and which character types to include: uppercase, lowercase, numbers and symbols. You can drop look-alike characters such as l, 1, O and 0 when a password has to be read aloud or typed from paper, and generate up to 50 passwords at once when setting up several accounts or devices. Every password is guaranteed to contain at least one character from each type you select, so it passes typical website rules.
Alongside the password you get its entropy in bits, a plain-English strength rating and an estimate of how long an offline attacker making 10 billion guesses per second would need on average. For accounts that matter, current NIST guidance (SP 800-63B, Revision 4, August 2025) favours length over complexity: it sets a 15-character minimum for passwords used on their own (8 when the password is only one factor of multi-factor sign-in) and tells sites to accept at least 64 characters. Use a unique password on every site and store them in a password manager. The crack-time figure is an illustration based on that single assumed guessing speed, not a guarantee.
How to use the password generator
- 1Set the password length — 16 or more is a good default.
- 2Choose which character types to include; keep symbols on unless a site forbids them.
- 3Turn on “Avoid look-alike characters” if you will read or type the password by hand.
- 4Check the strength rating and crack time, then copy the password.
- 5Save it in a password manager and never reuse it on another site.
Formula and method
Every character is chosen independently and uniformly from the pool of allowed characters using crypto.getRandomValues. With a pool of N characters and a length of L, there are N^L possible passwords, which is L × log₂(N) bits of entropy. The pool is 26 uppercase + 26 lowercase + 10 digits + 25 symbols = 87 characters with everything switched on; removing look-alikes drops it to 81.
On average an attacker has to try half of all possibilities, so the expected crack time is 2^(H−1) guesses divided by the guessing speed. We assume a fast offline attack of 10 billion guesses per second against a leaked hash; online attacks are far slower. Forcing one character from each type removes a tiny fraction of combinations, so the true entropy is marginally lower than shown.
- H
- Entropy in bits
- L
- Password length in characters
- N
- Number of characters in the allowed pool
Worked examples
Default 16-character password (all types)
With uppercase, lowercase, digits and 25 symbols the pool is 87 characters. 16 × log₂(87) ≈ 103.1 bits of entropy — far beyond what any offline attack can search, so it rates Very strong.
8-digit numeric PIN-style code
Digits only give a pool of 10, so 8 characters are just 10⁸ = 100 million combinations (26.6 bits). At 10 billion guesses per second that falls in well under a second — fine for a phone PIN with lockouts, useless as a website password.
Easy-to-read 20-character password
Removing I, O (upper), l, o (lower) and 0, 1 (digits) leaves 24 + 24 + 8 = 56 characters. Twenty of them give 20 × log₂(56) ≈ 116.1 bits, and five separate passwords are generated at once.
Frequently asked questions
How long should a password be?+
NIST SP 800-63B (Revision 4, 2025) requires at least 15 characters for passwords used on their own and at least 8 for passwords used only with a second factor, and it bars sites from forcing character-mix rules because length matters more. A random 16-character password from this generator has over 100 bits of entropy.
Is it safe to use an online password generator?+
This one runs entirely in your browser: passwords are created with the Web Crypto API and never sent to a server or saved. You can even disconnect from the internet after the page loads and it still works.
What makes a password strong?+
Length and randomness. A password is strong when it is long, generated randomly rather than chosen by a person, and unique to one account. Predictable patterns like Summer2026! are weak even though they mix character types.
What is password entropy?+
Entropy measures how many guesses a password could take, in bits. Each extra bit doubles the search space. Below about 36 bits is weak, 60–80 bits is strong for most uses, and 128 bits is beyond brute force.
Should I use symbols in my password?+
Symbols enlarge the character pool from 62 to 87, adding about 0.5 bits per character. That helps, but adding four more characters adds more. Leave symbols on unless a site rejects them.
How do I remember a random password?+
You should not have to. Store random passwords in a password manager and memorise only its master password, which is best made as a long passphrase of random words.