Password Generator

Generate strong random passwords (4 to 128 characters) with your browser's secure random generator, or check a password's strength and time to crack. Pick character types and symbols, exclude look-alike characters, create up to 50 at once, and see the exact entropy. Passwords are never saved or sent.

About this tool

What does the Password Generator do?

A strong password is long and truly random, so it cannot be guessed from words, patterns or personal information. This tool creates such passwords with crypto.getRandomValues, the cryptographically secure random number generator built into your browser, and shows how much entropy they have. A second tab estimates the strength of a password you already use.

How to use

Generate

  1. Open the Generate tab.
  2. Set the Length with the slider or the number field (default 16).
  3. Select the character types: Uppercase (A-Z), Lowercase (a-z), Digits (0-9) and Symbols. Edit Symbols to use if a site only allows certain symbols.
  4. Optionally check Exclude ambiguous characters and Include at least one of each selected type.
  5. Set the Count (1 to 50). Passwords are regenerated whenever a setting changes; click Generate for a new set.
  6. Click the copy icon next to a password, or Copy all to copy them one per line.

Check strength

  1. Open the Check strength tab.
  2. Type a password into Password to check (use the eye icon to show or hide it).
  3. See the rating, estimated entropy, warnings about weak patterns, and estimated crack times.

Features

  • Length from 4 to 128 characters
  • Custom symbol set (whitespace and control characters are ignored), with a button to restore the default: all 32 printable ASCII symbols
  • Exclude ambiguous characters removes 0, O, o, 1, l, I, the vertical bar, the backtick and quotes, which are easy to misread
  • Uniform random selection using rejection sampling, so no character is more likely than another (no modulo bias)
  • With Include at least one of each selected type, passwords missing a type are discarded and regenerated, keeping all valid passwords equally likely
  • Exact entropy for the current settings, including the effect of the "one of each type" rule
  • Strength checker that detects repeats (aaa, abcabc), sequences (abc, 123), keyboard patterns (qwerty, asdf), years and common passwords, including simple substitutions like p@ssw0rd

How much entropy is enough?

SettingsEntropy
8 characters, all four typesabout 52 bits
12 characters, letters and digitsabout 71 bits
16 characters, all four types (default)about 105 bits

The tool rates entropy as Very weak (under 28 bits), Weak (28 to 35), Fair (36 to 59), Strong (60 to 79) and Very strong (80 or more). Crack times are estimated for three scenarios: an online rate-limited attack (10 guesses/second), an offline attack on a slow hash such as bcrypt (10 thousand/second), and an offline attack on a fast hash on GPUs (10 billion/second).

FAQ

Are generated passwords stored or sent anywhere?

No. Passwords are generated in your browser and are not saved or transmitted. Only the settings (length, character types, symbols, count) are remembered, and there is no history.

Is the strength check accurate?

It is a simple estimate. It knows patterns and a small list of common passwords, but not dictionary words or personal information, so a password made of ordinary words or names may be rated higher than it deserves. Randomly generated passwords are always the safer choice.

Why are some symbols missing from my password?

Each character is chosen at random from the whole set, so a given symbol may not appear. Enable Include at least one of each selected type to guarantee at least one symbol, and edit Symbols to use to limit symbols to the ones a site accepts.