Password Generator — Create Strong Random Passwords
Part of Text tools: See all Text tools.
What is Password Generator?
This password generator creates a random password from 8 to 128 characters. You choose which character sets it draws from (lowercase letters, uppercase letters, numbers and symbols), and you can leave out look-alike characters such as 0, O, 1, l and I. Each character is picked with your browser's cryptographic random number generator, and the password is never sent to our server.
How to use Password Generator
- Set the length. The default is 16 characters; use 20 or more for important accounts if the site allows it.
- Tick the character sets you want. Leave all four on unless the site rejects symbols or other characters.
- Tick Exclude look-alikes if someone will read the password and type it by hand, for example a Wi-Fi password printed on a card.
- Click Generate, check the entropy line under the password, then click Copy and save it in your password manager straight away.
Why use this tool?
When people choose their own passwords they pick words, names and dates, and password-cracking tools try exactly those first. A password drawn at random from a large set of characters has no pattern to guess, so its strength depends only on its length and the size of the character pool. Generating it in your browser means it never passes through our server.
Don't overthink it: Use a long random password and store it in a password manager. Avoid reusing passwords across accounts - reuse is where most breaches start.
If a site supports it, consider a passphrase-style password (long words + random separators) for better memorability.
The real threat is not what most people picture
When people imagine "someone guessing my password", they picture an attacker sitting at a login screen typing guesses. That attacker is almost irrelevant — every serious site locks an account or throttles after a handful of wrong attempts, so online guessing tops out at a trivially small number of tries. The real threat is offline: a service you use gets breached, its database of password hashes is stolen, and the attacker runs those hashes through dedicated cracking hardware that tries billions of candidates per second on their own machines, with no rate limit and all the time in the world. A strong, randomly generated password is your defence against that scenario, which is the one that actually compromises accounts at scale. Designing for the offline attacker is why length and randomness matter so much more than the old "one capital and one number" folklore.
Entropy: the only password-strength number that means anything
Password strength is measured in bits of entropy — a precise statement of how many guesses an attacker needs on average. Each bit doubles the work. The maths is simple: a password drawn randomly from an alphabet of N possible characters and L characters long has roughly L × log₂(N) bits of entropy. A lowercase-only alphabet has 26 symbols (about 4.7 bits each); adding uppercase makes 52 (5.7 bits); adding digits makes 62 (5.95 bits); adding this generator's 26 symbols makes 88 (about 6.46 bits each). So a 16-character password using all four character classes carries roughly 16 × 6.46 ≈ 103 bits of entropy. At a billion guesses per second, exhausting 103 bits takes longer than the age of the universe by an absurd margin. That is the entire point of generating rather than choosing.
The crucial word is randomly. The entropy formula only holds if every character is chosen independently and uniformly. A human-chosen password like Summer2024! technically contains 11 characters from a large alphabet, but its actual entropy is a fraction of the theoretical figure because attackers know humans pick dictionary words, capitalise the first letter, and append a year and a bang. Crackers feed exactly those patterns first. Randomness is what closes the gap between theoretical and real strength, and it is the one thing a generator provides that a human brain cannot.
"Cryptographically strong" is not marketing
There are two kinds of random-number source in software, and the difference is the whole ballgame for passwords. An ordinary pseudo-random generator (the kind behind a typical random() call) is built for speed and statistical evenness, not secrecy — its output is predictable if you know or can deduce its internal seed, and attackers have reconstructed "random" passwords by doing exactly that. A cryptographically secure generator is specifically designed so that observing any amount of its past output gives no usable advantage in predicting the next, drawing from the operating system's entropy pool. A password is only as unguessable as the randomness behind it, so generating from a cryptographic source — not a convenience PRNG — is what makes those 103 bits real rather than nominal.
Length beats complexity (and the ambiguous-character trick)
Given a choice between adding one more character class and adding more characters, length wins almost every time, because length adds entropy linearly without limit while character classes add it only once and with diminishing returns. A 20-character lowercase-and-digit password is stronger than a 10-character everything-included one. This is also why passphrases — several random words strung together — can be both strong and memorable: their entropy comes from length and word choice rather than symbol soup. For passwords you will type by hand, leaning on length is usually the more practical path to strength than maximising symbol variety.
The option to exclude ambiguous characters — the look-alikes 0/O and 1/l/I — trades a sliver of entropy for a lot of real-world reliability. It matters when a password will be read off a screen and typed elsewhere, dictated over the phone, or printed on a setup card, where mistaking a zero for a capital O causes a frustrating failed login. For a password going straight into a password manager that you will only ever copy and paste, leave the look-alikes in and keep the extra entropy; for one a human has to transcribe, excluding them is the kinder choice.
A generated password is only half the system
The hardest security rule to follow is the most important one: a unique password for every account. Reuse is what turns one company's breach into the loss of your email, your bank, and your shopping accounts all at once — attackers take the credentials leaked from a weak site and immediately try them everywhere else (this is called credential stuffing, and it is automated and relentless). But nobody can memorise dozens of 16-character random strings, which is the real reason reuse persists. The answer is to pair a generator with a password manager: the generator makes the unique high-entropy string, the manager remembers it and fills it in, and your brain only has to hold one strong master password. That combination — not heroic memorisation — is how strong, unique passwords become practical for an ordinary person with a hundred accounts.
Matching the password to the system's rules
A maximally strong password is useless if the target site rejects it, and many do impose quirky constraints: a maximum length (sometimes frustratingly short), a ban on certain symbols, or a requirement for at least one of each class. Generate within those constraints rather than fighting them — set the length to the system's maximum, toggle off any forbidden symbol classes, and make sure the required classes are enabled, then confirm the site actually accepts the result before you save it and move on. One more habit worth keeping: treat any password you have ever pasted into a chat, an email, or a shared document as compromised and regenerate it. The generator runs in your browser and does not transmit or store what it produces, but the moment a password leaves a secure channel its entropy no longer protects you — so generate it, store it in your manager, and never let it travel in plain text.
Frequently asked questions
- Is this password generator safe to use?
- The password is generated by JavaScript in your browser using crypto.getRandomValues, the browser's cryptographically secure random source. It is not sent to our server, logged or stored. Once you close or reload the page it is gone, so save it in a password manager before you leave.
- How long should my password be?
- For most accounts, 16 random characters using all four character sets is plenty: about 103 bits of entropy. For a password manager's master password or your main email account, 20 or more characters is a sensible choice. If a site caps the length, use the longest it allows.
- What does the entropy figure mean?
- Entropy is the length multiplied by log2 of the pool size, which is the number of different characters the generator can pick from. Each extra bit doubles the number of guesses an attacker would need. The tool calls under 45 bits weak, 45 to 63 fair, 64 to 79 strong and 80 or more very strong. The figure holds because every character is chosen at random; it does not apply to a password you made up yourself.
- Why exclude look-alike characters?
- 0 and O, the characters 1, l and I, and the | symbol are easy to confuse when a password is read from paper or a screen and typed by hand. Ticking Exclude look-alikes removes 0, O, o, 1, l, I and |. With all four sets on, that shrinks the pool from 88 to 81 characters, which costs about 0.1 bits per character, so add a character if it matters to you.
- Which symbols does it use?
- The symbol set is ! @ # $ % ^ & * ( ) _ + - = [ ] { } | ; : , . < > ? which is 26 characters. If a site rejects some symbols, untick Symbols and add a little length instead: 16 letters and numbers from a pool of 62 still gives about 95 bits.
- Does every password include each character type I ticked?
- Yes. If a generated password happens to miss one of the sets you ticked, the tool draws a fresh one, so with Numbers ticked the password always contains at least one digit. Characters are picked without modulo bias, so every character in the pool is equally likely.
Step-by-step guides
Also try
Related tools that work well with this one: