Password Generator

Generate a strong random password entirely in your browser. Nothing you generate here is ever sent to a server.

Processed locally in your browser. Your data is not uploaded to our servers.

Click Generate to create a password

Entropy: —

16

Examples

Example configurations and their approximate entropy (higher is stronger):

LengthCharacter typesApprox. entropy
8Lowercase only~38 bits (weak)
12Upper + lower + numbers~71 bits (strong)
20All character types~131 bits (very strong)

Formula & Methodology

Password entropy (in bits) estimates how hard the password is to guess by brute force:

entropy = length × log2(character pool size)

This is a guideline, not a guarantee — entropy assumes an attacker doesn't know your specific method or reuse patterns.

How to Use

  1. Adjust the length slider and select which character types to include.
  2. Click Generate to create a password.
  3. Click Copy to copy it to your clipboard, or Regenerate for a new one.

Frequently Asked Questions

Is my generated password sent anywhere?

No. Passwords are generated entirely in your browser using the Web Crypto API and are never transmitted, logged, or stored — not even in this browser’s local storage.

Why use crypto.getRandomValues() instead of Math.random()?

Math.random() is not cryptographically secure and can be predictable. crypto.getRandomValues() uses your operating system’s secure random number generator, which is appropriate for generating passwords.

What does "exclude ambiguous characters" do?

It removes characters that are easily confused with each other when read or typed, such as 0 (zero), O (capital o), 1 (one), l (lowercase L), and I (capital i).

Is a longer password always stronger?

Generally yes — length contributes more to entropy (unpredictability) than character variety alone. Aim for at least 16 characters for important accounts where the service allows it.

Last updated: