Password Generator

Generate strong random passwords with an entropy meter.

Options

Character sets
Passwords regenerate when options change.

Generated passwords

How to generate a password

Pick a Length and Quantity, tick the character sets you want, then press Generate again for a fresh batch. Passwords regenerate automatically whenever an option changes. Copy them all at once or download them as passwords.txt. Everything runs in your browser, so nothing generated is uploaded or stored.

Entropy and strength

Entropy (in bits) measures how many guesses an attacker needs on average: each extra bit doubles the search space. Rough crack times below assume an offline attacker trying 10 billion guesses per second versus an online login that allows about 10 guesses per second (before rate limiting or lockouts kick in).

StrengthEntropyOffline (≈10¹⁰ guesses/sec)Online (≈10/sec)
WeakBelow 40 bitsMinutesCenturies
Fair40–59 bitsMinutes to yearsMillennia
Strong60–79 bitsYears to millenniaEffectively never
Very strong80–127 bitsMillions of yearsEffectively never
Excellent128 bits and upLonger than the age of the universeEffectively never

The default settings (20 characters from all four sets) give roughly 123–131 bits depending on the ambiguous-character option, comfortably in the Very strong to Excellent range.

Examples

SettingsSample shape
Length 12, letters + digits 12 mixed letters and digits, no symbols (example output, yours differ)
Length 20, all sets, no ambiguous 20 characters with upper, lower, digits and symbols (example output, yours differ)
Length 32, symbols only 32 symbols such as ! # % & * (example output, yours differ)

Limits and edge cases

  • Randomness comes from crypto.getRandomValues, a cryptographically secure source.
  • Draws use rejection sampling, so there is no modulo bias toward any character.
  • Generated passwords are never stored: only your option choices are kept in local storage.
  • Ambiguous characters (Il1O0) are excluded by default so passwords are easy to read and retype.
  • Symbols deliberately exclude quotes, backslash and backtick so passwords paste safely into shells, SQL, CSV and code.
  • Every password is guaranteed at least one character from each enabled set.

Frequently asked questions

Are my generated passwords stored anywhere?

No. Passwords are generated in your browser and are never saved, sent to a server, or written to local storage. Only your option choices (length, character sets) are remembered so the tool opens the way you left it.

What is password entropy?

Entropy measures unpredictability in bits. A 20-character password drawn from 70 possible symbols has about 123 bits of entropy, meaning an attacker would need around 2 to the power of 123 guesses to be sure of finding it. More bits means exponentially harder to crack.

What are ambiguous characters and why exclude them?

Ambiguous characters are look-alikes: capital I, lowercase l, digit 1, capital O and digit 0. They are excluded by default so passwords are easier to read aloud, transcribe and type without confusing one character for another.

Why does every password include each selected character set?

Guaranteeing at least one character from every enabled set prevents weak surprises, such as a symbols-enabled password that randomly contains no symbols. It also satisfies password policies that require mixed character types.

How many passwords can I generate at once?

You can generate between 1 and 100 passwords at a time, each between 4 and 256 characters long. Bulk generation is handy when provisioning accounts or rotating many credentials in one go.

Is anything I generate uploaded to a server?

No. The generator runs entirely in your browser using your device's cryptographic random number source. Nothing you generate or configure is uploaded anywhere.