How many characters should a password be?
Quick answer
At least 16 characters for ordinary accounts, per current guidance from CISA and similar bodies - longer is better, and modern NIST guidance allows passwords up to 64 characters. Length matters more than symbol variety for resisting brute-force attacks.
Free, no sign-up, and your file is read on your own device rather than uploaded.
Password guidance has shifted in recent years: length now matters more than a specific mix of character types. A 20-character passphrase can be both easier to remember and harder to crack than a 10-character jumble of symbols, because each additional character multiplies the number of attempts a brute-force attack needs, while additional symbol complexity in a short password only adds so much.
Sixteen characters is a reasonable minimum for everyday accounts today; anything you can make longer without real inconvenience is worth doing, especially for high-value accounts like email and password managers.
Step by step
Choose a length
16 characters minimum for most accounts, 20+ for anything high-value like email or a password manager master password.
Password GeneratorGenerate it
A random password using the full range of character types, generated with a cryptographically secure random source.
Password Generator
Tips
- A password manager removes the need to remember long random passwords at all - you only need to remember one master password, which is exactly where the extra length matters most.
- Current guidance has moved away from mandatory periodic password changes - change one when there is an actual reason to (a breach, a shared device), not on an arbitrary schedule.
Common problems
A site rejects a long, randomly generated password.
Some older systems cap password length or reject certain symbols - if this happens, generate again with a shorter length or without special characters rather than abandoning a strong password entirely.
Frequently asked questions
- Is a longer password really safer than a complex short one?
- Generally yes - length has a larger multiplying effect on how long a brute-force attack takes than adding symbol variety to a short password does.
- What is the maximum useful password length?
- Current NIST guidance permits up to 64 characters. Beyond a certain point (well past 16-20 characters) the practical security benefit levels off, though a longer passphrase is never worse.
- Does this password generator store what it creates?
- No - generation uses your browser's cryptographically secure random source, and nothing generated is transmitted or stored anywhere.
Related related tools
- Password GeneratorCreate strong random passwords that never leave your browser.
- Hash GeneratorGenerate SHA-1, SHA-256, SHA-384 and SHA-512 hashes as you type.
Related articles
Ready to do it?
Free, no sign-up, and nothing is uploaded to a server.
