Generate a strong password

Strong random passwords, generated on your device and never transmitted.

Include
 
 

123 bits of entropy · strong enough for anything

Generated on your device with the browser’s cryptographic random source, and never sent anywhere.

A generated password only helps if it was generated properly: from a cryptographic random source, long enough, and never sent across the internet on its way to you.

This uses your browser’s own cryptographic generator — not Math.random(), which is predictable — and the result never leaves the page. There is no request to look at in the network tab because there isn’t one.

The strength is shown in bits of entropy, which is the honest measure: it says how many guesses an attacker needs, rather than colouring a bar green because you added an exclamation mark.

A word of advice worth more than the generator: use a password manager. Unique long passwords are only workable if something remembers them for you.

How to use it

  1. Choose a length (20 characters is a good default).
  2. Pick which character types to include.
  3. Copy the password, or generate a batch at once.

Frequently asked questions

How long should a password be?

With all character types on, 16 characters is beyond brute force today and 20 leaves room for the future. For a master password you type by hand, a passphrase of five or six random words is easier to live with.

What do the bits mean?

Bits of entropy: each extra bit doubles the number of guesses needed. Under 50 is weak, 75 is comfortable, 90+ is not being guessed by anyone.

Are the passwords sent to your server?

No. They are generated in your browser and never transmitted. You can verify that by generating one with your network connection off.

Why avoid look-alike characters?

Because l, 1, I, O and 0 get mistyped when a password has to be read aloud or copied by hand. Leave the option off if you’re pasting into a manager anyway.

More free tools

All generators →