Skip to content

Free tool

Password generator

Strong passwords, passphrases and PINs, made in your browser. Nothing is sent or saved.

Generated locallyNot stored
Generating…
No password yet0 bits
characters
Characters

Every type you pick appears at least once.

Leaves out I l 1 O 0 o. Handy if someone has to read it aloud or type it.

Need to send it to someone? Don't paste it into chat.

Recent

The last 10, in this tab's memory only. Gone on reload.

Values you generate show up here.

Check a password

Runs in this page. What you type is never sent or saved.

Don't type a password you use today into any website, this one included.

No password yet0 bits

Type a password to see an estimate.

Offline, fast hash10 billion/s
—
A leaked database hashed with MD5 or SHA-1, on a GPU rig.
Online, against a login10,000/s
—
A service that doesn't throttle wrong attempts well.

A rough estimate from a short built-in list of common passwords and patterns. It can tell you a password is weak; it can't prove one is strong. Generated passwords are measured exactly instead.

Guide

What makes a password strong

Randomness, not cleverness
A password is as strong as the number of equally likely options it was picked from. Swapping a for @ in a word adds almost nothing; attackers try those swaps first.
Length beats symbols
Each extra character multiplies the work. A 20-character lowercase password is stronger than a 10-character one with every symbol on the keyboard.
One password per site
Most accounts are broken with passwords leaked from somewhere else. A unique password for each site stops one breach from becoming ten.
Let a manager remember them
Use a password manager for the long random ones. Keep one strong passphrase in your head to unlock it.

Passphrases

Words you can type, entropy you can count

A passphrase is a few words picked at random, like harbor-velvet-pilot-ember. Each word from our 1,629-word list adds about 10.7 bits. Five words give about 53 bits, six about 64. The words must be chosen by the generator, not by you: people pick words that go together, and attackers know it.

Turn on Capitalize or Include a number when a site insists on them. They add a little entropy, but adding a word adds more.

Privacy

Why it runs in your browser

Generating a password on a server means trusting that server not to keep a copy. This page doesn't ask for that trust. It draws from crypto.getRandomValues, rejects biased samples so every character is equally likely, and never makes a network request with the result. History stays in this tab's memory and is gone on reload.

FAQ

Questions

Is this password generator safe to use?

Passwords are made in your browser with crypto.getRandomValues, the operating system's secure random source, and are never sent anywhere. The page loads from our server like any website, but the generator makes no network requests. The code is open source under the MIT license.

How long should a password be?

For a random password with letters, digits and symbols, 16 characters gives about 100 bits of entropy, which is far out of reach of any known guessing attack. If a site caps length, use the longest it allows and turn on every character type it accepts.

Are passphrases better than passwords?

Neither is better by nature. Strength comes from how many equally likely choices there were. Six random words from our 1,629-word list give about 64 bits; a random 10-character password using every character type gives about the same. Passphrases are easier to type and remember, so use them for things you unlock by hand, such as a password manager or a laptop.

What do the crack times mean?

They are the average time to guess the password if the attacker knows exactly how it was generated. Offline assumes 10 billion guesses a second against a leaked database with a fast hash such as MD5 or SHA-1. Online assumes 10,000 guesses a second against a login. Slow hashes like bcrypt or Argon2 make offline guessing thousands of times slower.

Do you store the passwords I generate?

No. The history on this page lives in the tab's memory and is gone when you reload or close it. Nothing is written to local storage, cookies or our servers.

Does the password checker send my password anywhere?

No. The checker runs in the page. It compares your password against a short built-in list of common passwords and patterns, so it can only say a password looks weak, never prove it is strong. Don't type a password you use today into any website, including this one.

How do I send a generated password to someone?

Don't paste it into chat or email, where it stays forever. Copy it, open a Secure Note, and send the link. The note is encrypted in your browser and can delete itself after one read.

Related tools