How to use the password Generator
- Choose the password length. 16 characters or more is a good default for accounts you care about.
- Choose how many passwords to generate.
- Tick the character types to include. Every ticked type is guaranteed to appear at least once.
- Tick Avoid look-alikes if you'll ever need to read or type the password by hand.
- Press Generate again for new passwords, then Copy result, or select a single line.
- The result updates instantly as you type. There is no button to press.
- Use Copy result to copy the figures, or Copy link to share a link that reopens the password Generator with the same inputs.
How it works
A strong password is long and truly random. Passwords people invent tend to follow patterns, such as a word, a capital letter at the start and a number and symbol at the end, and attackers' cracking tools try those patterns first. A random password has no pattern to exploit, so the only way to break it is to try every possibility.
This generator uses your browser's cryptographically secure random number generator (crypto.getRandomValues), the same source used for encryption keys, and rejection sampling so every character in the pool is exactly equally likely. Passwords are created on your device and are never sent anywhere or stored. The page's share link only remembers your settings, never the passwords.
Strength is measured in bits of entropy: length × log₂(pool size). Each extra bit doubles the number of guesses needed. A 16-character password from all four character types (90 symbols) has about 104 bits, far beyond what any attacker can brute-force. The guessing time shown assumes an attacker making 10 billion guesses per second against a stolen password database, which is realistic for fast hash algorithms, and that on average they find it halfway through. Use a different password for every site and store them in a password manager.
Formula
Pool sizes: lowercase 26, uppercase 26, digits 10, symbols 28. Avoiding look-alike characters removes O, o, 0, I, l, 1 and |.
Example
A 16-character password drawn from all four sets uses a pool of 90 characters, so it has 16 × log₂(90) ≈ 104 bits of entropy: about 1.9 × 10³¹ possible passwords. An 8-character password of lowercase letters only has 8 × 4.7 ≈ 38 bits, which a fast offline attack could exhaust in well under a minute.
Frequently asked questions
How long should a password be?
At least 12 characters for everyday accounts, and 16 or more for email, banking and password-manager master passwords. Length adds strength faster than extra character types do.
Are these passwords stored anywhere?
No. They are generated in your browser and disappear when you close or regenerate the page. They are not included in the share link.
Is a passphrase better than a random password?
A passphrase of four or more random words, chosen by a random process rather than by you, is easier to remember and can be just as strong. Random character passwords are best when a password manager remembers them for you.