Password Generator
Generate cryptographically secure random passwords with customizable length (8-128 characters) and character types. Uses your browser's built-in crypto API. Passwords are never saved or sent to any server.
Key features
- Passwords with letters, numbers, and special symbols
- Adjustable length from 8 to 128 characters
- Live password strength meter
- Generated on your device and never stored
Guide
Passwords are the first line of defense for every online account, server, database, API key, and encrypted file. A weak password can be cracked in seconds by modern hardware. A strong password generated with sufficient randomness is practically unguessable even with the most powerful computing resources available. This tool generates cryptographically random passwords with customizable length, character sets, and formats. ## What Makes a Password Strong Password strength comes from two factors: length and randomness (entropy). Entropy is measured in bits. Each bit of entropy doubles the number of possible passwords an attacker must try. A password with 80 bits of entropy has 2^80 possible values, which is about 1.2 x 10^24 combinations. For a password using the full printable ASCII set (uppercase, lowercase, digits, and 32 special characters = 95 characters total), each character adds about 6.57 bits of entropy (log2(95)). A 12-character password has about 79 bits, a 16-character password has about 105 bits, and a 20-character password has about 131 bits. For comparison, a password using only lowercase letters (26 characters) gets 4.7 bits per character. A 12-character lowercase-only password has only 56 bits of entropy. That is why mixing character types matters: it increases the character set size, which increases per-character entropy. Current recommendations from NIST (SP 800-63B), OWASP, and security researchers: use at least 12 characters for standard accounts and 16+ characters for high-value targets (admin accounts, master passwords, encryption keys). Length is more important than complexity. A 20-character lowercase password (94 bits) is stronger than an 8-character password with all character types (52 bits). The key insight: password strength depends entirely on how the password was generated, not on how complex it looks. The password P@ssw0rd! looks complex to a human but is trivially crackable because it follows a predictable pattern (common word + common substitutions + trailing symbol). A truly random 12-character string like xk7Qm2nR4pLs has no pattern for an attacker to exploit. ## How Cryptographic Randomness Works This tool uses the Web Crypto API (crypto.getRandomValues()) to generate random numbers. This is a cryptographically secure pseudorandom number generator (CSPRNG) provided by your operating system. It draws entropy from hardware sources like mouse movements, keyboard timings, disk access patterns, network packet arrival times, and dedicated hardware random number generators (Intel RDRAND, ARM TRNG). CSPRNG output is fundamentally different from Math.random(). Math.random() uses algorithms like xorshift128+ that produce statistically random-looking output but are fully deterministic and predictable if you know the internal state. An attacker who observes a few outputs of Math.random() can predict all future outputs and recover past outputs. This has been demonstrated in practice. crypto.getRandomValues() does not have this weakness because it continuously mixes in new hardware entropy. Never use Math.random() for generating passwords, tokens, session IDs, nonces, encryption keys, or any security-sensitive values. Always use crypto.getRandomValues() in the browser, crypto.randomBytes() in Node.js, secrets.token_bytes() in Python, SecureRandom in Java, or /dev/urandom on Unix systems. The tool converts random bytes to password characters using rejection sampling. It generates a random number, checks if it falls within the valid character set range, and discards values that fall outside (to avoid modulo bias). This ensures each character in the password has equal probability, which maximizes entropy. ## Password Generation Options Length: The single most important parameter. Every additional character multiplies the time an attacker needs by the size of the character set. Adding one character to a password with a 95-character set multiplies the attack time by 95. Set the minimum to 12 for general use, 16 for important accounts, and 20-32 for encryption keys and master passwords. Uppercase letters (A-Z): 26 characters. Almost always included. Required by most password policies. Lowercase letters (a-z): 26 characters. Almost always included. The backbone of most passwords. Digits (0-9): 10 characters. Include these to satisfy most password policies. Some systems require at least one digit. Special characters (!@#$%^&*()-_=+[]{}|;:',.<>?/~`): These add significant entropy per character because they expand the character set. Some services restrict which special characters are allowed. Common restrictions: no spaces, no quotes, no backslashes. If a generated password is rejected, try regenerating with a simpler special character set (just !@#$%^&*) or check the service's password requirements. Exclude ambiguous characters: This removes characters that look similar in many fonts: 0 (zero) vs O (letter O), 1 (one) vs l (lowercase L) vs I (uppercase I), 5 vs S, 8 vs B. Enable this when the password will be read aloud over the phone, written on paper, printed on a label, or displayed in a monospace font where these characters are hard to distinguish. Custom character set: Some systems restrict passwords to specific character sets. If a service only allows alphanumeric characters plus a few symbols, you can configure the generator to use only those characters and increase the length to compensate for the smaller set. ## Types of Passwords Random character passwords like x7#Kp9$mQ2&nL4 are the strongest per character but impossible to memorize. Use these with a password manager. They are ideal for any account where you will not need to type the password from memory. Passphrases like correct-horse-battery-staple use random words instead of random characters. A 4-word passphrase from a 7,776-word list (like the EFF Diceware wordlist) has about 51 bits of entropy. A 6-word passphrase has about 78 bits. A 7-word passphrase has 90 bits. Passphrases are easier to type on mobile devices and easier to memorize, but are longer in character count. Use passphrases for your master password and for passwords you must type from memory. PIN codes are numeric passwords used for phone locks, banking, ATMs, and 2FA backup codes. A 4-digit PIN has only 13.3 bits of entropy (10,000 combinations). A 6-digit PIN has 19.9 bits (1,000,000 combinations). Use at least 6 digits for PINs, and 8+ digits for anything serious. PINs are inherently weak and should only be used with lockout mechanisms that limit attempts. This tool focuses on random character passwords. For passphrases, use a dedicated generator like the EFF Diceware page or Bitwarden's passphrase option. ## Password Entropy Calculations Here are exact entropy values for common configurations: - 8 chars, lowercase only: 37.6 bits (crackable in minutes on a modern GPU) - 8 chars, mixed case + digits: 47.6 bits (crackable in hours) - 8 chars, mixed case + digits + symbols: 52.6 bits (crackable in hours to days) - 10 chars, mixed case + digits + symbols: 65.7 bits (crackable in weeks) - 12 chars, lowercase only: 56.4 bits (borderline) - 12 chars, mixed case + digits: 71.5 bits (solid for most uses) - 12 chars, mixed case + digits + symbols: 78.8 bits (strong) - 14 chars, mixed case + digits + symbols: 92 bits (very strong) - 16 chars, mixed case + digits + symbols: 105 bits (very strong) - 20 chars, mixed case + digits + symbols: 131 bits (extremely strong) - 24 chars, mixed case + digits + symbols: 157 bits (overkill for most purposes) For context, the Bitcoin mining network operates at about 5 x 10^20 hashes per second. At that rate, brute-forcing an 80-bit entropy password would take about 38 years. 100 bits would take 38 million years. At 128 bits, the sun will burn out before the password is cracked. These numbers assume the attacker is hashing passwords as fast as the entire Bitcoin network mines blocks, which is unrealistically generous to the attacker. Password cracking in practice uses GPUs running hashcat or John the Ripper. A single RTX 4090 GPU can compute about 164 billion MD5 hashes per second, 68 billion SHA-1 hashes per second, or 22 billion SHA-256 hashes per second. Against bcrypt (cost 12), the same GPU manages only about 105,000 hashes per second. This is why proper password hashing functions (bcrypt, scrypt, Argon2) are so important on the server side. ## When to Use This Tool New account registration: Generate a unique password for every new account. Never reuse passwords across services. If one service is breached, reused passwords let attackers access all your other accounts. This attack, called credential stuffing, is responsible for the majority of account takeovers. API keys and tokens: When a service asks you to create a secret key or API token, use the generator instead of typing something from memory. A 32-character random alphanumeric string provides about 190 bits of entropy. Database credentials: Set strong passwords for database users, especially the admin/root account. Database breaches through weak credentials are common. Set a 24+ character random password for production databases. Encryption passphrases: For encrypting files with GPG, VeraCrypt, 7-Zip, or OpenSSL, use a long random password. Store it in your password manager. The encryption is only as strong as the passphrase. WiFi passwords: Your WPA2/WPA3 password should be at least 16 random characters. A weak WiFi password allows anyone within signal range to capture and brute-force the handshake offline. SSH key passphrases: Protect your SSH private key with a strong passphrase generated here. If your private key is stolen (from a backup, a compromised laptop, or a cloud storage breach), the passphrase is the only thing preventing the attacker from using it. Service accounts: Automated systems (CI/CD pipelines, monitoring, backup scripts) that authenticate with passwords should use long random passwords. These passwords are never typed by humans, so length and complexity cost nothing. ## Common Mistakes Mistake 1: Using predictable patterns. Passwords like Summer2026!, Company@123, qwerty!@#, or Welcome1 follow patterns that attackers check first. Password cracking tools use rule-based attacks that try common patterns: word + year + symbol, word + number + number, word with common substitutions (a to @, e to 3, s to $). These rules crack most human-chosen passwords in minutes. Mistake 2: Making passwords too short to satisfy complexity requirements. If a site requires a special character and you change "password" to "password!\
Frequently asked questions
How secure is my password?
Passwords use cryptographically secure randomness from your browser's crypto API. They cannot be predicted or guessed.
Are passwords saved somewhere?
No. When you refresh the page, the password is gone. No server, no logs, no history.
Is this a free alternative to password manager generators?
Yes. Generate cryptographically random passwords here for free with no extension or account required.
Related guides
- Online Privacy Tools That Never Phone Home: Passwords, Hashes, and Tokens in Your Browser
- Password Generator Entropy Explained, Pools Bits and Bias
- UUID v4 vs UUID v7: Which UUID Version to Use
