About the Password Generator
This creates strong, random passwords to your specification — you choose the length and which character types to include (uppercase, lowercase, digits, symbols), and it builds a password and rates its strength. Random passwords beat anything you'd invent yourself, because human-chosen passwords follow predictable patterns that attackers exploit. Use it to set up a new account, replace a weak or reused password, or generate a one-off credential — ideally paired with a password manager so you never have to remember it.
Prefer a memorable word-based passphrase instead of random characters? See the Passphrase Generator.
How it works
Every character is drawn using your browser's cryptographically secure random generator (crypto.getRandomValues), not the ordinary Math.random, so the output is suitable for real security use. It assembles a character pool from the types you've enabled, optionally removes ambiguous characters (i l 1 L o 0 O) that are easy to misread, then picks characters from that pool. The strength meter shows the password's entropy in bits, calculated as length × log₂(pool size) — the higher the bits, the more guesses an attacker would need.
What makes a password strong
Strength comes mostly from length and randomness, not from cramming in symbols. Each extra character multiplies the number of possibilities, so a long random password of even one character type can beat a short one with all types. As a rough guide, the meter treats under ~40 bits as weak, ~60 as fair, ~90+ as strong to very strong. The single most effective habit is a unique random password per site, stored in a password manager — reuse is what turns one breach into many.
Assumptions and behaviour
- Uses secure (CSPRNG) randomness, so passwords are unpredictable and never repeat by design.
- Ambiguous-character removal is optional and shrinks the pool slightly (which marginally lowers entropy for the same length).
- Entropy is reported as
length × log₂(pool size), the standard measure for a randomly generated password. - The character pools are: 26 uppercase, 26 lowercase, 10 digits, and a set of common symbols.
Limitations
- It doesn't guarantee at least one of each selected type. Characters are drawn from the combined pool, so a short password could, by chance, contain no digit even with digits enabled — regenerate if a site's rules require one of each.
- Some sites reject certain symbols or cap length; you may need to adjust the settings to fit their rules.
- The entropy figure assumes truly random generation (which this is); it doesn't estimate strength against patterns, because these passwords have none.
- A password is only as safe as where you store it — don't paste it somewhere insecure.
- Need a short numeric PIN instead (e.g. for a device lock)? Use the PIN Generator.
Privacy
Passwords are generated entirely in your browser with its built-in crypto. Nothing is uploaded, logged, or stored — close the tab and the password is gone unless you saved it.

