Password Generator

Strong passwords and API keys from your browser’s cryptographic random source, never a server.

20
Characters
Strength128 bits · Very strong

Far beyond brute force. The length is no longer the weak link — how it is stored is.

85 possible characters × 20 positions

    API key or secret

    For things a machine reads rather than a person types. Measured in bytes of entropy, not characters.

    Everything here is generated in your browser using crypto.getRandomValues. Nothing is transmitted, logged or stored — which is the only basis on which you should trust any password generator.

    How it works

    1. 1Set a length and choose which character types to include. Everything regenerates as you change the options.
    2. 2Entropy is shown in bits — the honest measure of strength — along with what that number actually means.
    3. 3"Avoid look-alikes" removes the characters people confuse when reading a password aloud or copying it by hand.
    4. 4The secret generator at the bottom is for API keys: random bytes rendered as hex or base64url, not a typeable password.

    Common questions

    Is it safe to generate a password on a website?
    Only if it is generated in your browser and never transmitted, which is what happens here — the code runs locally using crypto.getRandomValues. You can verify that by opening the network tab and watching nothing leave. A generator that produces passwords on a server is one you should not use.
    What does "bits of entropy" mean?
    The base-2 logarithm of how many passwords the settings could produce. Each extra bit doubles the search space. Under 40 bits is trivially crackable; 80 is beyond brute force for most purposes; above 110 the password is no longer the weak point.
    Is longer better than more symbols?
    Almost always, yes. Going from 12 to 16 lowercase-only characters adds more entropy than adding symbols to a 12-character password. Length scales linearly in bits, alphabet size only logarithmically.
    Why does the strength bar ignore dictionary words?
    Because these passwords are random — there are no words in them to find. Entropy is the correct measure for randomly generated strings. It is the wrong measure for a password a human invented, where "Summer2024!" scores well and falls in seconds.
    Should I reuse one strong password everywhere?
    No. Strength does not help when the site storing it is breached. Generate a different one per account and keep them in a password manager — that is the actual fix, and this tool is a reasonable way to feed one.
    What length should I use?
    16 to 20 characters for an ordinary account with a password manager holding it. Longer for anything protecting other credentials. Under 12 is not worth generating.

    Storing these, not just making them?

    A password is only as safe as how it is hashed at the other end. If you are building the system, the Hash Generator shows what SHA digests look like — and why they are the wrong tool for passwords.

    Open the Hash Generator

    Related tools