Password Generator
Strong passwords and API keys from your browser’s cryptographic random source, never a server.
20
Strength128 bits · Very strong
Far beyond brute force. The length is no longer the weak link — how it is stored is.
85 possible characters × 20 positions
API key or secret
For things a machine reads rather than a person types. Measured in bytes of entropy, not characters.
Everything here is generated in your browser using crypto.getRandomValues. Nothing is transmitted, logged or stored — which is the only basis on which you should trust any password generator.
How it works
- 1Set a length and choose which character types to include. Everything regenerates as you change the options.
- 2Entropy is shown in bits — the honest measure of strength — along with what that number actually means.
- 3"Avoid look-alikes" removes the characters people confuse when reading a password aloud or copying it by hand.
- 4The secret generator at the bottom is for API keys: random bytes rendered as hex or base64url, not a typeable password.
Common questions
- Is it safe to generate a password on a website?
- Only if it is generated in your browser and never transmitted, which is what happens here — the code runs locally using crypto.getRandomValues. You can verify that by opening the network tab and watching nothing leave. A generator that produces passwords on a server is one you should not use.
- What does "bits of entropy" mean?
- The base-2 logarithm of how many passwords the settings could produce. Each extra bit doubles the search space. Under 40 bits is trivially crackable; 80 is beyond brute force for most purposes; above 110 the password is no longer the weak point.
- Is longer better than more symbols?
- Almost always, yes. Going from 12 to 16 lowercase-only characters adds more entropy than adding symbols to a 12-character password. Length scales linearly in bits, alphabet size only logarithmically.
- Why does the strength bar ignore dictionary words?
- Because these passwords are random — there are no words in them to find. Entropy is the correct measure for randomly generated strings. It is the wrong measure for a password a human invented, where "Summer2024!" scores well and falls in seconds.
- Should I reuse one strong password everywhere?
- No. Strength does not help when the site storing it is breached. Generate a different one per account and keep them in a password manager — that is the actual fix, and this tool is a reasonable way to feed one.
- What length should I use?
- 16 to 20 characters for an ordinary account with a password manager holding it. Longer for anything protecting other credentials. Under 12 is not worth generating.
Storing these, not just making them?
A password is only as safe as how it is hashed at the other end. If you are building the system, the Hash Generator shows what SHA digests look like — and why they are the wrong tool for passwords.
Open the Hash Generator