Technology & Developers
Free Password Generator
Create strong random passwords that never leave your browser.
Free to useNo sign-up requiredNo watermarkRuns in your browser
This free password generator creates strong random passwords using your browser's cryptographic random number generator - not the ordinary pseudo-random function most scripts reach for, which is not fit for anything security-related.
The password is generated on your device, is never transmitted, and is never stored. Reload the page and it is gone, so copy the one you want into your password manager before you leave.
How this tool works
Set the length
Sixteen characters or more is a sensible minimum. Length contributes far more strength than complexity does.
Choose the character types
Lower case, upper case, digits and symbols. Turn off anything a particular site refuses to accept.
Generate and copy
Five options are produced at once. Copy one straight into your password manager.
How it works
Characters are drawn using crypto.getRandomValues, the browser's cryptographically secure source of randomness. Math.random is never used - it is predictable enough that passwords built with it can be reconstructed.
Values from the top of the byte range are discarded rather than wrapped, so no character is more likely than any other. Skipping that step introduces a small but real bias that weakens the result.
Strength is reported as entropy in bits, calculated from the size of the character set and the length. Each extra bit doubles the effort needed to guess it.
Nothing is stored, logged or transmitted. There is no history, and closing the tab discards everything.
What actually makes a password strong
- Length above everything. A sixteen-character password of only lower-case letters is far stronger than an eight-character one with symbols.
- Randomness. A password you invented follows patterns you are not aware of. Substituting 3 for e and @ for a is the first thing cracking tools try.
- Uniqueness. Reuse is what turns one breach into many. A unique password per site limits the damage to that one account.
- A password manager, so unique random passwords are practical to actually use.
- Two-factor authentication wherever it is offered - it protects the account even if the password is exposed.
Entropy, roughly translated
| Under 40 bits | Trivially guessable with modern hardware |
|---|---|
| 40 to 60 bits | Weak; adequate only for throwaway accounts |
| 60 to 80 bits | Reasonable for most everyday accounts |
| 80 to 110 bits | Strong; suitable for email and banking |
| Over 110 bits | Very strong; appropriate for master passwords and keys |
Worked examples
A master password
Twenty-four characters with all types enabled gives well over 110 bits - appropriate for the one password protecting everything else.
A password you must type by hand
Turn on "avoid look-alike characters" so 0 and O, 1 and l cannot be confused, and go longer to make up for the smaller alphabet.
A site that rejects symbols
Turn symbols off and add a few characters of length instead - the strength is easily recovered.
Frequently asked questions
Is this password generator free?
Yes, free with no sign-up and no limit on how many passwords you generate.
Are the passwords sent anywhere or saved?
No. They are generated in your browser, never transmitted and never stored. There is no history and no log - reload the page and they are gone permanently.
How random are they really?
They use crypto.getRandomValues, the browser's cryptographically secure generator, with rejection sampling so that no character is favoured. This is the same class of randomness used for encryption keys.
How long should my password be?
At least sixteen characters for ordinary accounts, and twenty or more for email, banking and password manager master passwords. Length matters more than symbol variety.
Should I change passwords regularly?
Current guidance says no - forced rotation pushes people towards predictable variations. Change a password when there is a reason to: a breach, a shared device, or any suspicion of exposure.
