A password generator makes passwords no one can guess, because nothing about them was chosen by a person. Set the length and the characters, or switch to a passphrase of random words, and copy the result. The strength is shown as entropy in bits, with what that means in plain English.
Your password
Out of reach of any realistic guessing attack. At a trillion guesses a second: about 207 billion years.
Characters
Made in your browser with crypto.getRandomValues. Nothing is uploaded, stored or logged, and the password never leaves this page unless you copy it.
A new password is made whenever you change an option, and Generate makes a fresh one with the same settings. Every character type you pick is guaranteed to appear at least once, so the password passes "must contain a number and a symbol" rules first time.
How to use it
- Pick Password for random characters or Passphrase for random words.
- For a password, drag Length anywhere from 8 to 128 characters and pick the characters to use: lower case, upper case, numbers and symbols. Turn on Leave out look-alikes if you will ever read it out or type it by hand.
- For a passphrase, pick how many Words, the Separator between them, and whether to Capitalise each word or Add a number.
- Check the strength under the password, then tap Copy and paste it into your password manager.
How strong is strong enough?
Entropy is the number of equally likely passwords the generator could have made, as a power of two. The attack times assume a trillion guesses a second, what a rack of graphics cards manages against a leaked database with a fast hash.
| Entropy | Label | Example | Time to crack at 10¹² guesses/s |
|---|---|---|---|
| under 40 bits | Very weak | 8 digits | under a second |
| 40 to 59 bits | Weak | 8 letters and numbers | under a second to days |
| 60 to 79 bits | Fair | 6-word passphrase | days to thousands of years |
| 80 to 127 bits | Strong | 16 characters, all types | thousands of years and up |
| 128 bits and up | Very strong | 20 characters, all types | longer than the universe has existed |
A site that stores passwords properly, with a slow hash such as bcrypt or Argon2, makes each guess thousands of times more expensive, so these are the worst case. A login form that limits attempts is safer still. Aim for the worst case anyway: you do not get to choose how a site stores your password.
Password or passphrase?
| Random password | Passphrase | |
|---|---|---|
| Looks like | q7#Vd9!mRw2^xKp4 | acorn-blimp-grape-tulip-oven-crisp |
| Entropy | about 103 bits at 16 characters | about 62 bits at 6 words |
| Easy to remember | No | Yes |
| Easy to type on a phone | No | Yes |
| Best for | Everything your password manager fills in | Your password manager's master password, device logins, Wi-Fi |
Add words to close the gap: 8 words is about 83 bits and 10 is about 103, the same as a 16-character password.
How this generator works
- Secure randomness. Every character and word comes from
crypto.getRandomValues, the browser's cryptographic random number generator.Math.randomis never used: it is fast but predictable enough that it should never make a secret. - No modulo bias. A random 32-bit number turned into one of 89 characters
with
% 89lands on the first few characters slightly more often, because 2³² is not a multiple of 89. The generator discards the handful of values at the top of the range that cause this and draws again, so every character is exactly as likely as any other. - Every type you pick, without a pattern. A password missing one of the selected character types is thrown away and redrawn, rather than having a digit and a symbol forced into fixed places. The result is uniform over every password that meets the rule, and the entropy shown counts exactly that set.
- Symbols that paste cleanly. The symbol set is ASCII punctuation minus the
quote marks, backslash, backtick and
|, the five characters that break shell commands, JSON and config files, or look like a lower-case l.
Generating a password in code
The same rules apply in code: use the language's secure random source, never the general-purpose one.
| Language | Secure | Not for passwords |
|---|---|---|
| JavaScript | crypto.getRandomValues() | Math.random() |
| Python | secrets.choice(), secrets.token_urlsafe() | random.choice() |
| C# | RandomNumberGenerator.GetInt32() | new Random() |
| Java | SecureRandom | java.util.Random |
| Go | crypto/rand | math/rand |
In Python, "".join(secrets.choice(alphabet) for _ in range(16)) is a complete,
unbiased password generator.
Password gotchas
- One password per account. Reusing a strong password makes it only as safe as the weakest site you used it on. A password manager makes unique passwords painless.
- Length limits. Some sites cap passwords at 16, 20 or 64 characters and some silently cut off the rest. If a new password will not work, try a shorter one rather than a weaker one.
- Banned symbols. A few sites reject certain symbols. Turn off symbols and add length to keep the entropy up: 20 letters and numbers is about 119 bits.
- Changing passwords on a schedule is no longer recommended by NIST. Change one when there is a reason to, such as a breach.
- Do not store passwords as plain text or in a reversible form. If you are building the login side, hash them with a slow algorithm such as Argon2 or bcrypt.
Related
- UUID Generator for random IDs. A UUID is an identifier, not a secret, so use this page for anything that must stay hidden.
- Base64 Encoder and Decoder. Base64 is an encoding, not encryption: anyone can decode a Base64 "password" in one click.
- Typing Speed Test, for when a passphrase is the thing you have to type every morning.
- The Bash cheat sheet:
openssl rand -base64 24makes a random password in a terminal, from the same kind of secure source. - The Python cheat sheet for the
secretsmodule and the rest of the standard library.
Common questions
Is this password generator safe to use?
Yes. The password is made in your browser with crypto.getRandomValues, the operating system's secure random number generator, and is never uploaded, stored or logged. The page records only that the tool was used and the settings picked, such as the length, never the password itself. You can load the page, switch off your connection, and it still works.
What makes a strong password?
Length and true randomness. A strong password is long, at least 16 characters, drawn at random from a large set of characters, and used for one account only. Clever substitutions like P@ssw0rd add almost nothing, because cracking tools try them first. This strong password generator shows the strength as entropy in bits: aim for 80 bits or more for anything that matters.
What is password entropy?
Entropy is how many guesses an attacker would need, written as a power of two. A password with 60 bits of entropy is one of 2^60 equally likely possibilities, so each extra bit doubles the work. It depends only on how the password was made: the length and the size of the character set, or the number of words and the size of the word list. It is not a guess about how the password looks.
How long should a password be?
16 characters with letters, numbers and symbols gives about 103 bits of entropy, which is out of reach of any realistic guessing attack, and it is the default here. Go to 20 or more for a password manager's master password or an encryption key. Only go below 12 if a site forces you to, and use every character type it allows.
What is a passphrase, and is it better than a password?
A passphrase is several random words joined together, such as acorn-blimp-grape-tulip-oven-crisp. It is not stronger per character, but it is far easier to remember and to type, which makes it the better choice for anything you type by hand: a master password, a computer login or a Wi-Fi key. This passphrase generator uses the EFF short word list of 1,296 words, so each word adds about 10.3 bits, and six words give about 62.
Why leave out look-alike characters?
Capital I, lower-case l, the number 1, capital O and the number 0 look the same in many fonts. If you will ever read the password aloud, copy it from a screen or type it on a TV remote, leave them out. It shortens the character set slightly, and the entropy shown drops to match.
Is a random password generator really random?
This one is, in two ways that matter. It uses crypto.getRandomValues rather than Math.random, which is not built for secrets. And it avoids modulo bias: turning a random number into a character with a simple remainder makes some characters slightly more likely than others, so the generator throws away the few random values that would cause that and draws again.