Password Generator
Generate strong random passwords with an entropy meter.
Options
Generated passwords
How to generate a password
Pick a Length and Quantity, tick the character sets you want, then press
Generate again for a fresh batch. Passwords regenerate automatically whenever an option
changes. Copy them all at once or download them as passwords.txt. Everything runs in your
browser, so nothing generated is uploaded or stored.
Entropy and strength
Entropy (in bits) measures how many guesses an attacker needs on average: each extra bit doubles the search space. Rough crack times below assume an offline attacker trying 10 billion guesses per second versus an online login that allows about 10 guesses per second (before rate limiting or lockouts kick in).
| Strength | Entropy | Offline (≈10¹⁰ guesses/sec) | Online (≈10/sec) |
|---|---|---|---|
| Weak | Below 40 bits | Minutes | Centuries |
| Fair | 40–59 bits | Minutes to years | Millennia |
| Strong | 60–79 bits | Years to millennia | Effectively never |
| Very strong | 80–127 bits | Millions of years | Effectively never |
| Excellent | 128 bits and up | Longer than the age of the universe | Effectively never |
The default settings (20 characters from all four sets) give roughly 123–131 bits depending on the ambiguous-character option, comfortably in the Very strong to Excellent range.
Examples
| Settings | Sample shape |
|---|---|
| Length 12, letters + digits | 12 mixed letters and digits, no symbols (example output, yours differ) |
| Length 20, all sets, no ambiguous | 20 characters with upper, lower, digits and symbols (example output, yours differ) |
| Length 32, symbols only | 32 symbols such as ! # % & * (example output, yours differ) |
Limits and edge cases
- Randomness comes from
crypto.getRandomValues, a cryptographically secure source. - Draws use rejection sampling, so there is no modulo bias toward any character.
- Generated passwords are never stored: only your option choices are kept in local storage.
- Ambiguous characters (
Il1O0) are excluded by default so passwords are easy to read and retype. - Symbols deliberately exclude quotes, backslash and backtick so passwords paste safely into shells, SQL, CSV and code.
- Every password is guaranteed at least one character from each enabled set.
Frequently asked questions
Are my generated passwords stored anywhere?
No. Passwords are generated in your browser and are never saved, sent to a server, or written to local storage. Only your option choices (length, character sets) are remembered so the tool opens the way you left it.
What is password entropy?
Entropy measures unpredictability in bits. A 20-character password drawn from 70 possible symbols has about 123 bits of entropy, meaning an attacker would need around 2 to the power of 123 guesses to be sure of finding it. More bits means exponentially harder to crack.
What are ambiguous characters and why exclude them?
Ambiguous characters are look-alikes: capital I, lowercase l, digit 1, capital O and digit 0. They are excluded by default so passwords are easier to read aloud, transcribe and type without confusing one character for another.
Why does every password include each selected character set?
Guaranteeing at least one character from every enabled set prevents weak surprises, such as a symbols-enabled password that randomly contains no symbols. It also satisfies password policies that require mixed character types.
How many passwords can I generate at once?
You can generate between 1 and 100 passwords at a time, each between 4 and 256 characters long. Bulk generation is handy when provisioning accounts or rotating many credentials in one go.
Is anything I generate uploaded to a server?
No. The generator runs entirely in your browser using your device's cryptographic random number source. Nothing you generate or configure is uploaded anywhere.