Strong password generator

Generate a strong random password of 8 to 64 characters, or a passphrase of random words. Choose upper case, lower case, digits and symbols, and hide look-alike characters. The tool shows the entropy in bits and a strength rating. Passwords are made in your browser and never stored or sent.

Free, no sign-up Runs in your browser

Your password

Options

Every ticked type appears at least once.

Only these settings are saved in your browser. Passwords never are.

How this password generator works

Each character is picked with crypto.getRandomValues, the browser's cryptographically secure random number generator. It does not use Math.random, which is not designed for security.

Picking fairly takes care. A random 32-bit number has 4,294,967,296 possible values. With all four character types there are 89 characters to choose from, and 4,294,967,296 is not a multiple of 89. Taking the remainder after dividing by 89 would make a few characters very slightly more likely than others. This tool discards random numbers from that uneven tail and draws again (rejection sampling), so every character has exactly the same chance.

To make sure each type you ticked appears at least once, the tool generates the whole password and, if a type is missing, throws it away and starts again. Every password that meets your rules is equally likely, so the entropy figure is exact. Nothing is sent to a server, and the password is never saved.

Password entropy explained

Entropy measures how many guesses an attacker would need, as a power of two. A password with 60 bits of entropy is one of 260 (about 1018) equally likely possibilities. For a random password, entropy is roughly length × log2(number of possible characters):

Characters usedPoolBits per character12 chars16 chars20 chars
Digits only103.32405366
Lower case264.70567594
Upper and lower case525.706891114
Letters and digits625.957195119
All four types (this tool)896.4878104130

The tool's figure is slightly lower than the table, because requiring every type rules out some combinations. For 16 characters with all four types it shows about 103 bits rather than 104.

The strength label is a rule of thumb, not a standard: under 40 bits is weak, 40–59 fair, 60–79 strong and 80 or more very strong. Entropy only describes randomly generated passwords. A password you invent, such as Summer2026!, is far weaker than its length suggests, because attackers try common patterns first.

Password or passphrase?

A passphrase is a few random words, such as Maple-Otter-Prism-Canoe-Velvet-Torch. It is easier to type and remember than a random string. Each word comes from a built-in list of 757 short, common English words, so each word adds log2(757) ≈ 9.6 bits:

WordsEntropyRating here
438 bitsWeak
657 bitsFair
767 bitsStrong
986 bitsVery strong

Capitalising each word and the choice of separator make a passphrase easier to read but add no entropy, because they are the same every time. The words must be picked at random. A phrase you choose yourself, like a song lyric, is much easier to guess.

Tips for safer passwords

  • Use a different password for every account. When one site is breached, attackers try the same email and password on other sites.
  • Use a password manager to store them. Then length costs you nothing: 20 random characters are as easy as 8.
  • Turn on two-factor authentication for email, banking and anything else important.
  • Prefer length to complexity. NIST's digital identity guidelines (SP 800-63B) favour long passwords over composition rules and advise against forcing regular password changes.
  • Exclude look-alikes when you will read a password aloud or type it from paper. It removes I, l, 1, O and 0 and costs only a little entropy.

Frequently asked questions

Is this password generator safe to use?
Yes. Passwords are created in your browser with the Web Crypto API (crypto.getRandomValues). They are never sent over the network and never saved. Only your settings, such as length and character types, are remembered on this device.
How long should my password be?
For important accounts, use at least 16 random characters with all four character types, which gives about 103 bits of entropy. If you use a password manager, 20 or more characters costs you nothing extra.
Is a passphrase as secure as a random password?
It can be, if it is long enough and the words are chosen at random. With this tool's 757-word list, 7 words give about 67 bits and 9 words about 86 bits. A 16-character random password gives about 103 bits.
What does "bits of entropy" mean?
It is the number of yes-or-no guesses needed to cover every possible password, as a power of two. Each extra bit doubles the work for an attacker. 80 bits means 280 possibilities.
Which symbols are used?
27 symbols: ! @ # $ % ^ * ( ) - _ = + [ ] { } ; : , . ? / ~, plus the ampersand and the less-than and greater-than signs. Quotes, backslashes, backticks and spaces are left out because some websites and command lines handle them badly.
Why exclude look-alike characters?
Capital I, lower-case l and the digit 1 look alike in many fonts, as do capital O and zero. Excluding them avoids mistakes when you read or type a password by hand.

Last updated . How we check our tools.