Password Generator
Generate strong, random passwords with crypto-grade randomness. Pick a length, choose your character sets, and check the entropy strength meter.
Last updated: October 2026
Password options
What password entropy means
Entropy measures password strength in bits. If each character is drawn uniformly from a pool of N possible characters, and the password has L characters, the total number of possible passwords is N raised to the power L. Entropy is the base-2 logarithm of that number:
Every extra bit doubles the attacker's work. A 16-character password from the full 94-character set (upper, lower, digits, 32 symbols) has 16 x log2(94), which is about 104.9 bits. That means roughly 2^105 guesses to exhaust the space on average, half that for a 50 percent chance. At 10 billion guesses per second, a machine would need far longer than the age of the universe.
| Password | Pool | Entropy | Verdict |
|---|---|---|---|
| 8 lowercase letters | 26 | 37.6 bits | Weak: crackable in hours |
| 8 mixed characters | 94 | 52.4 bits | Weak: crackable with GPUs |
| 12 mixed characters | 94 | 78.7 bits | Fair: safe against most attackers |
| 16 mixed characters | 94 | 104.9 bits | Strong: beyond brute force |
| 20 mixed characters | 94 | 131.1 bits | Very strong: massive margin |
Why the randomness source matters
This generator uses crypto.getRandomValues, the browser's interface to the operating system's cryptographic randomness. That matters because many casual generators use Math.random, a deterministic pseudorandom generator. Given a few outputs or a lucky guess at its internal state, an attacker can predict every password Math.random will ever produce. Crypto-grade randomness is designed so that even an attacker who watches all your previous passwords learns nothing about the next one. If your browser does not provide a crypto source, this generator refuses to produce a password rather than silently falling back to the weak one.
The generator also guarantees that every selected character set appears at least once, then shuffles the result with crypto-grade randomness. Without that step, a "16-character mixed" password could theoretically come out all lowercase, quietly dropping your entropy from 104.9 bits to 75.2.
Worked example
With the default settings (length 16, all four sets on, ambiguous allowed), the pool is 26 + 26 + 10 + 32 = 94 characters. Entropy = 16 x log2(94) = 16 x 6.5546 = 104.9 bits. The strength meter reads "Very strong", and the crack-time estimate at 10 billion guesses per second is on the order of 10^21 years. Turning on "exclude ambiguous" removes I, l, 1, O, and 0, shrinking the pool to 89 and entropy to 16 x log2(89) = 103.6 bits: a negligible cost for much easier manual reading.
Practical password hygiene
Unique per site. Reuse is the top real-world password risk. Breaches leak plaintext or crackable hashes constantly; a unique password per site keeps one breach from becoming all of them. A password manager remembers them so you do not have to.
Length beats complexity tricks. Substitutions like "p@ssw0rd" add almost no entropy against modern cracking dictionaries, but four extra random characters multiply the search space by 94^4, about 78 million times. When in doubt, go longer, not weirder.
Turn on two-factor authentication. Even a 104-bit password cannot help if a phishing page captures it. A second factor, ideally a hardware key or authenticator app rather than SMS, covers the human weak point.
One passphrase to memorize. You only need to remember your password manager's master password. Make it a passphrase of five or more randomly chosen words: easy to type, hard to guess, and the single key that protects everything else.
Password generator FAQs
Why does this generator use crypto.getRandomValues instead of Math.random?
Math.random is a predictable pseudorandom generator: if an attacker learns its internal state, they can predict every future password it makes. crypto.getRandomValues draws from the operating system's cryptographic randomness source, which is designed to be unpredictable. For passwords, predictability is the whole ballgame, so the weaker generator is never acceptable.
What is password entropy?
Entropy measures password strength in bits: entropy = length x log2(pool size), where the pool is the number of possible characters in each position. A 16-character password drawn from 94 possible characters has 16 x log2(94), about 104.9 bits. Every extra bit doubles the number of guesses an attacker needs on average.
How long should my password be?
For anything important, use at least 16 characters from the full character set, which gives about 105 bits of entropy. That is far beyond brute force with any foreseeable hardware. Shorter passwords are fine for low-value accounts, but length beats complexity: a 20-character lowercase-only password (94 bits) is stronger than an 8-character mixed one (52 bits).
What does exclude ambiguous characters do?
It removes characters that look alike in many fonts: capital I, lowercase l, the digit 1, capital O, and the digit 0. This helps when you must read or type a password manually, for example from a printed sheet. It shrinks the pool slightly, from 94 to 89 characters, which costs a fraction of a bit per character.
Are my generated passwords stored or sent anywhere?
No. Passwords are generated in your browser and never transmitted, logged, or saved. When you close or refresh the page they are gone. This also means you should copy any password you intend to keep into a password manager immediately.
Should I use a random password or a passphrase?
Both work if they are long enough. A random 16-character password is ideal for accounts because you never type it, your password manager does. A passphrase of 5 or more random words is better for the one master password you must memorize, since it is easier to type correctly while still carrying high entropy.
Can I reuse a generated password on multiple sites?
Do not. Reuse is the single biggest password risk: one breached site hands attackers the key to every other account sharing it. Generate a unique password per site and let a password manager remember them, so a breach anywhere stays contained.