Password generator
Generate strong passwords locally in your browser.
How to use
Choose a length between 8 and 128 characters (20 by default) and which character sets to draw from: uppercase letters, lowercase letters, numbers and the symbols !@#$%^&*()-_=+[]{}. Generate creates a new password every time you press it, and Copy puts it on the clipboard.
Every character comes from the browser’s cryptographic random source, and at least one character from each set you tick is included before the order is shuffled, so a password never misses a set you asked for. The password is generated in your browser and is not stored or sent anywhere.
Length beats variety, by a wide margin. Each character drawn from all four sets (80 possible characters) adds about 6.3 bits of entropy, so the default 20 characters give about 126 bits. Twenty lowercase letters give about 94 bits; eight characters from all four sets give only about 51. The longer, simpler one is more than ten trillion times harder to search.
If a site rejects some symbols, untick Symbols and add a few characters of length instead: 22 letters and numbers are stronger than 16 characters with symbols. For a password you must remember and type, a passphrase of several random words is easier to handle; this tool generates character passwords, which belong in a password manager.
Example
Generates a fresh 20-character password using all four character groups. Each run produces a different result.
20 characters, all setsAbout 126 bits of entropy: the default, and plenty for any account.20 characters, lowercase onlyAbout 94 bits.8 characters, all setsAbout 51 bits: far weaker, despite the symbols.A site that refuses symbolsUntick Symbols and use 22 characters or more.
Frequently asked questions
Do symbols make a password stronger?
A little, and much less than adding characters. Every extra character multiplies the search space; adding symbols only widens the alphabet once. If you have to choose, choose longer.
Is a generated password safe to reuse?
No password is, however strong. Strength decides how long it survives a cracking attempt; reuse decides how many accounts fall when one site is breached. Those are separate problems, and only a password manager solves the second.
Is the generated password stored anywhere?
No. It exists only on the page until you copy it or leave; nothing is logged or sent.
What does entropy mean here?
A measure of how many passwords are possible: n bits means 2ⁿ possibilities, so an attacker trying them all would need up to 2ⁿ guesses. Each extra bit doubles the work.