Make a strong random password

Strong random passwords, made on your device.

How it works

  1. Pick a type
  2. Adjust length and options
  3. Copy

How these passwords are made

Every character, word and digit comes from your browser's Web Crypto API, the browser's cryptographic random number generator. The tool turns those numbers into choices without bias: when a random number would favour some characters over others, it is thrown away and drawn again. For Random characters you set a length from 8 to 64 and tick which types to include: uppercase letters, lowercase letters, digits and symbols. With all four ticked the tool draws from 94 characters. If a finished password is missing one of the types you ticked, the whole password is discarded and a new one is drawn, up to 1000 times. It never swaps a character in afterwards, because that would make some passwords more likely than others. Avoid look-alikes removes O, 0, I, l and 1, which is useful when you must read a password aloud or type it from paper. This tool never uses Math.random. If your browser has no secure random source, it shows a message and makes nothing.

Passwords vs passphrases vs PINs

A random password packs the most strength into the fewest characters, which suits a password manager that fills it in for you. A passphrase is a few random words from a list of 7,776, such as four words joined by hyphens. It is longer to type but much easier to remember and to read out, so it suits the one password you must know by heart, such as the one that unlocks your password manager. The words are picked independently, so the phrase is random, not a sentence you chose. A PIN is digits only, from 4 to 12. A 6-digit PIN has about 20 bits of entropy, which is why this tool labels it Weak. A PIN protects something only when the device or service locks you out after a few wrong guesses, so it is only as safe as that lock-out.

What entropy bits mean

Entropy counts how many equally likely outcomes the generator could have produced. Each bit doubles the number. A random password of 16 characters drawn from 94 symbols has 16 times log2(94), about 105 bits. The tool shows an estimate, always worded as about so many bits. The real figure for that default is slightly lower, around 104.6 bits, because discarding passwords that miss a ticked type removes a few possible outcomes. A passphrase gets 12.9 bits per word, so four words give about 52 bits, and an added digit gives 3.3 bits more. A PIN gets 3.3 bits per digit. The strength label is our own convention: under 40 bits is Weak, 40 to 59 Fair, 60 to 79 Strong, and 80 or more Very strong. It says how hard the value is to guess if it is random and secret. It says nothing about whether a site stores your password safely, and the tool gives no estimate of cracking time.

Privacy: nothing stored, nothing sent

The password is made in this tab and shown on screen. It is not sent to any server, not saved in your browser, not put in the page address and not included in the page's visit counts, which record only that a result appeared. Your choices, such as length and which types are ticked, are remembered on this device so the page opens as you left it. The password itself is not: reload the page and you get a new one, and an earlier password cannot be brought back. That also means this tool cannot store or recover a password for you. Copy it into a password manager before you close the tab. Copying puts the text on your device's clipboard, where other programs may read it, so paste it where you need it and then copy something else. The word list loads from this site the first time you open Passphrase.

Frequently asked questions

Is this password generator safe to use?

The password is made in your browser with the Web Crypto API and is not sent anywhere or saved. Nothing in this page can promise that the site you use it on stores it safely. Copy it straight into a password manager and do not reuse it on a second site.

Why not just use Math.random?

Math.random is not designed to be unpredictable, so it is the wrong tool for secrets. This tool uses crypto.getRandomValues with rejection sampling, so each of the 94 characters is equally likely. If that source is missing, it makes nothing instead of falling back.

How long should my password be?

For an account kept in a password manager, 16 random characters with all four types is a sound default, at about 105 bits. If you must type it by hand, a passphrase of 5 or 6 words gives about 65 to 78 bits. If a site rejects a long password or certain symbols, lower the length or untick Symbols.

Are look-alike characters safer?

No. Removing O, 0, I, l and 1 makes a password easier to read, not harder to guess, and costs a little strength: at 16 characters it drops the pool from 94 to 89 characters, about 104 bits. Use it when someone has to read the password aloud or copy it from paper.

Should I reuse a password I like?

No. If one site leaks it, anyone can try it on your email and bank. Make a new one per account and keep them in a password manager. This tool keeps no history, so it cannot remind you of an old password.

Where does the passphrase word list come from?

It is the EFF Large Wordlist by the Electronic Frontier Foundation, 7,776 words, shared under a Creative Commons Attribution (CC BY) licence. This tool shows the list's credit under the passphrase options and loads it only when you open Passphrase.