Password Generator
Cryptographically secure (crypto.getRandomValues), generated entirely in your browser — nothing is sent or stored. Pick the rules a site demands and copy.
How strong is strong enough?
- Estimated entropy describes the random search space from the length and alphabet. The display is an upper estimate: requiring characters from each selected set reduces that space. It is not a time-to-crack prediction.
- Online guessing depends on login rate limits. Offline cracking after a breach also depends on how the service hashes passwords and the attacker's hardware. There is no universal safe bit threshold.
- A randomly generated 20-character lowercase password has about 94 bits before extra constraints. This estimate does not apply to a phrase or pattern you invent yourself.
- Avoid ambiguous removes look-alike characters to make transcription easier. Keep any spoken, printed or written password private.
- Use a password manager for a long, unique password on each account, and enable multifactor authentication where available. Length cannot prevent phishing or malware. See NIST's password-strength guidance.
Runs 100% in your browser — your passwords are never sent over the network or saved anywhere. Close the tab and they're gone.