🔑 Password Generator

Strong random passwords generated on your device. Nothing is sent or stored.

What actually makes a password strong

Length, randomness, and uniqueness, in that order. A password's strength is measured in entropy: the number of unpredictable choices packed into it. Every extra character from a large character set multiplies the work an attacker needs, which is why a 16-character random password from this generator (around 100 bits of entropy) outlasts any clever pattern a human invents. Human patterns, swapped letters, a capital at the front, a number and a symbol at the end, are exactly what cracking tools try first, because millions of people all "randomise" the same way.

This generator uses your browser's cryptographic random source, the same one your bank's website relies on, with a sampling method that gives every character an exactly equal chance. It also guarantees that every character set you tick actually appears, and by default leaves out look-alike characters (0, O, 1, l, I) so the password survives being read aloud or typed from a sticky note. Nothing is transmitted or stored: close the tab and the password exists only where you saved it.

Frequently asked questions

How long should my passwords be?

16 characters is a solid default for important accounts, and there is rarely a reason to go below 12. For a Wi-Fi password or a master password you must type occasionally, 20 or more costs you nothing in a password manager and buys real margin.

Is it safe to generate passwords on a website?

On this one, the generation happens entirely in your browser; the password is never sent to a server, which you can verify by disconnecting from the internet and generating one anyway. That is the only safe model, and it is why this tool works offline in the downloaded preview too.

Why exclude look-alike characters?

Because passwords still get read off screens, emails and sticky notes in real life, and confusing 0 with O causes lockouts, not security. Excluding five ambiguous characters costs almost no entropy at these lengths.

Where should I keep a password like this?

In a password manager (your browser's built-in one, 1Password, Bitwarden and similar), never in a notes file or a spreadsheet. A strong password you reuse is a weak password: uniqueness per account is what limits a breach to one site.