🔐 Password Generator
Create strong, random passwords in your browser – choose the length and character types and see how hard each one is to crack.
Quick answer: Entropy = length × log₂(pool size). A 16-character password using uppercase, lowercase, digits and all 32 symbols draws from 94 characters, giving 16 × log₂ 94 ≈ 104.9 bits – very strong.
Updated · Free · No sign-up · Works on any device
Password Generator inputs
Result
Your new password
3-s]e?DP}dWm3`45
Generated in your browser with a cryptographically secure random generator – never sent anywhere.
| Strength | Very strong |
| Entropy | 104.9 bits |
| Character pool | 94 characters × 16 positions |
| Time to crack (100 billion guesses/s) | about 5,887 billion years |
5 more passwords
| # | Password |
|---|---|
| 1 | 0C);h9iI;fq]|W<A |
| 2 | AVB9!3^{c$OvwPD: |
| 3 | z_b6WM)*1~(c">J9 |
| 4 | ndMM_{{Z"~D1&Sz> |
| 5 | (O`gv\'8F/=FeH|0 |
Press Generate password again for a fresh set. Nothing is stored or transmitted.
What makes a password strong?
A strong password is long and truly random. Attackers try common words, leaked passwords and keyboard patterns first, so anything a human invents is weaker than it looks. A randomly generated password forces them to try every combination.
Entropy (bits) = length × log₂(number of possible characters)
Worked example
With uppercase (26), lowercase (26), digits (10) and symbols (32) the pool is 94 characters. A 16-character password therefore has 16 × log₂ 94 = 16 × 6.55 ≈ 104.9 bits of entropy – about 2¹⁰⁵ possibilities, far beyond the reach of any cracking rig.
Entropy by length
| Length | Letters + digits (62) | All four sets (94) |
|---|---|---|
| 8 | 47.6 bits | 52.4 bits |
| 12 | 71.5 bits | 78.7 bits |
| 16 | 95.3 bits | 104.9 bits |
| 20 | 119.1 bits | 131.1 bits |
Strength labels used here: under 40 bits weak, 40–59 fair, 60–79 good, 80–99 strong, 100+ very strong.
How this generator works
- Random numbers come from
crypto.getRandomValues, the same secure source browsers use for encryption keys. - Every chosen character type is guaranteed to appear at least once, then the characters are shuffled so their positions are unpredictable.
- Rejection sampling removes modulo bias, so every character is equally likely.
Password tips
- Use a different password for every account and store them in a password manager.
- Turn on two-factor authentication wherever it is offered.
- Never reuse a password that has appeared in a data breach.
Passphrases as an alternative
If you must memorise a password, a passphrase of five or six random dictionary words can be just as strong and easier to type. What matters is that the words are chosen randomly, not picked from a favourite quote or song.
Frequently asked questions
Is this password generator safe to use?
Yes. Passwords are created on your device using the browser's cryptographically secure random number generator (crypto.getRandomValues). They are never sent to a server or stored.
How long should my password be?
Use at least 12 characters for everyday accounts and 16 or more for email, banking and password-manager master passwords. Length adds far more strength than complexity.
What is password entropy?
Entropy measures how unpredictable a password is, in bits. Each extra bit doubles the number of guesses an attacker needs. Above about 80 bits is considered strong against offline attacks.
Why exclude look-alike characters?
Characters such as I, l, 1, O and 0 are easy to confuse when reading or typing a password by hand. Excluding them costs a little entropy, which you can recover by adding a character or two.