Password Generator

Generate a strong, random password with your choice of length and character sets.

Fx4m8!}HSFO-2-0Y
Very strong~103 bits of entropy

What is the Password Generator?

This tool generates random passwords using your browser's cryptographically secure random number generator (crypto.getRandomValues), not Math.random() — the difference matters, since Math.random() is predictable enough in some engines that it should never be used for anything security-related.

You control the length and which character sets are included, and can see roughly how strong the result is before you use it.

How to use it

  1. Adjust the length slider.
  2. Toggle which character sets to include — lowercase, uppercase, numbers, symbols.
  3. Optionally exclude visually ambiguous characters (like 1, l, I, 0, O) if you'll be typing the password by hand.
  4. Click "Copy," or "↻ Regenerate" for a new one with the same settings.

How it works

The generator builds a character pool from your selected sets, then uses crypto.getRandomValues() — the Web Crypto API's cryptographically secure random source — to pick one character from that pool per position, repeated for the chosen length.

The entropy estimate (bits) is calculated as length × log₂(pool size) — a standard measure of how many guesses a brute-force attacker would need on average.

Example

A 16-character password with all sets enabled might look like:

xQ7#mK2$pL9@vR4n

Frequently asked questions

Is this actually secure, or just "random-looking"?

It uses crypto.getRandomValues(), the same cryptographically secure randomness source used by security-critical browser APIs — not Math.random(), which is not designed to be unpredictable.

How long should my password be?

Longer is better. 12 characters is a reasonable minimum today; 16+ with all character sets enabled is comfortably strong for most purposes.

What does "bits of entropy" mean?

It's a measure of unpredictability — each additional bit doubles the number of guesses needed to brute-force the password. 60+ bits is generally considered strong against offline attacks.

Should I exclude ambiguous characters?

Only if you need to type or read the password manually (like writing it down) — it slightly reduces the character pool and therefore the strength for the same length.

Is my generated password sent anywhere or stored?

No — it's generated and displayed entirely in your browser and never leaves your device.