How to use the password generator
- Length — 8 to 128 characters. Longer is stronger; 16 or more is a good default when a password manager remembers it for you.
- Character types — turn off symbols only if a site rejects them, and add length to make up for it.
- Exclude look-alikes — removes I, l, 1, O and 0 for passwords you'll read aloud or type by hand.
- Press Generate new password for a fresh one (changing any setting also makes a new one), then use the Copy button.
How the password is generated
Characters come from the Web Crypto API (crypto.getRandomValues), the browser's cryptographically secure random number generator — not Math.random, which isn't designed to be unpredictable. Each character is picked with rejection sampling: the few random values that would make some characters slightly more likely than others are thrown away and redrawn, so every character in the pool is equally likely. The generator places at least one character from each type you selected, fills the rest from the full pool and shuffles the result.
Nothing is sent over the network or stored — copy the password into your password manager before you leave the page.
What entropy means
Entropy measures how hard a password is to guess, in bits: entropy = length × log₂(pool size). Each extra bit doubles the number of possible passwords. With all four types the pool has 89 characters (26 uppercase, 26 lowercase, 10 digits and 27 symbols), worth about 6.48 bits per character, so a 16-character password has about 103.6 bits. The formula only applies to randomly generated passwords; a password a person invents has much less entropy than its length suggests.
The table shows how long it would take to try every combination at an assumed 100 billion guesses per second — an illustrative figure for a fast offline attack against a stolen password database.
| Length (all four types) | Entropy (bits) | Time to try every combination | Rating here |
|---|---|---|---|
| 8 | 51.81 | 11 hours | Fair |
| 10 | 64.76 | 10 years | Fair |
| 12 | 77.71 | 78,267 years | Strong |
| 16 | 103.61 | 5 trillion years | Very strong |
| 20 | 129.51 | more than a quadrillion years | Very strong |
Ratings: under 50 bits weak, 50–64 fair, 65–89 strong, 90 or more very strong.
Passphrases
For the few passwords you must memorize — a password manager's master password or a computer login — a passphrase of random words is easier to remember and type. Its strength comes from the size of the word list. The EFF's diceware list has 7,776 words, so each randomly chosen word adds about 12.9 bits: five words give about 64.6 bits and six words about 77.5 bits. The words must be picked at random, with dice or a generator; a phrase you thought of yourself, a lyric or a quotation is far easier to guess.
Habits that matter more than any single password
- Never reuse a password. When one site is breached, attackers try the same email and password on other sites. A unique password for every account limits the damage to one account.
- Use a password manager. It generates, stores and fills a unique password for every site, so you only remember one strong passphrase.
- Turn on two-factor authentication for email, banking and social accounts, ideally with an authenticator app or a security key rather than text messages.
- Length beats tricks. NIST's digital identity guidelines (SP 800-63B) favor long passwords and advise against forced periodic changes and arbitrary composition rules. Change a password when there's a sign it was exposed.
Frequently asked questions
Is it safe to use an online password generator?
This one generates the password inside your browser with the Web Crypto API; nothing is transmitted or stored. Still, generate passwords on a device you trust, and save them straight into a password manager.
How long should my password be?
With a password manager there is no cost to length, so 16 to 20 random characters is a sensible default. For a password you must memorize, a random passphrase of five or six words is a good choice.
What does excluding look-alike characters do?
It removes I, l, 1, O and 0, shrinking the pool from 89 to 84 characters. A 16-character password drops from about 103.6 to 102.3 bits — a tiny cost for a password that is easier to read and type by hand.
What if a site does not allow symbols?
Turn symbols off and add a few characters. Sixteen characters of letters and digits give about 95.3 bits; adding two more characters takes it past 107 bits.
Last updated: October 8, 2026