How this password generator works
Each character is picked with crypto.getRandomValues, the browser's cryptographically secure random number generator. It does not use Math.random, which is not designed for security.
Picking fairly takes care. A random 32-bit number has 4,294,967,296 possible values. With all four character types there are 89 characters to choose from, and 4,294,967,296 is not a multiple of 89. Taking the remainder after dividing by 89 would make a few characters very slightly more likely than others. This tool discards random numbers from that uneven tail and draws again (rejection sampling), so every character has exactly the same chance.
To make sure each type you ticked appears at least once, the tool generates the whole password and, if a type is missing, throws it away and starts again. Every password that meets your rules is equally likely, so the entropy figure is exact. Nothing is sent to a server, and the password is never saved.
Password entropy explained
Entropy measures how many guesses an attacker would need, as a power of two. A password with 60 bits of entropy is one of 260 (about 1018) equally likely possibilities. For a random password, entropy is roughly length × log2(number of possible characters):
| Characters used | Pool | Bits per character | 12 chars | 16 chars | 20 chars |
|---|---|---|---|---|---|
| Digits only | 10 | 3.32 | 40 | 53 | 66 |
| Lower case | 26 | 4.70 | 56 | 75 | 94 |
| Upper and lower case | 52 | 5.70 | 68 | 91 | 114 |
| Letters and digits | 62 | 5.95 | 71 | 95 | 119 |
| All four types (this tool) | 89 | 6.48 | 78 | 104 | 130 |
The tool's figure is slightly lower than the table, because requiring every type rules out some combinations. For 16 characters with all four types it shows about 103 bits rather than 104.
The strength label is a rule of thumb, not a standard: under 40 bits is weak, 40–59 fair, 60–79 strong and 80 or more very strong. Entropy only describes randomly generated passwords. A password you invent, such as Summer2026!, is far weaker than its length suggests, because attackers try common patterns first.
Password or passphrase?
A passphrase is a few random words, such as Maple-Otter-Prism-Canoe-Velvet-Torch. It is easier to type and remember than a random string. Each word comes from a built-in list of 757 short, common English words, so each word adds log2(757) ≈ 9.6 bits:
| Words | Entropy | Rating here |
|---|---|---|
| 4 | 38 bits | Weak |
| 6 | 57 bits | Fair |
| 7 | 67 bits | Strong |
| 9 | 86 bits | Very strong |
Capitalising each word and the choice of separator make a passphrase easier to read but add no entropy, because they are the same every time. The words must be picked at random. A phrase you choose yourself, like a song lyric, is much easier to guess.
Tips for safer passwords
- Use a different password for every account. When one site is breached, attackers try the same email and password on other sites.
- Use a password manager to store them. Then length costs you nothing: 20 random characters are as easy as 8.
- Turn on two-factor authentication for email, banking and anything else important.
- Prefer length to complexity. NIST's digital identity guidelines (SP 800-63B) favour long passwords over composition rules and advise against forcing regular password changes.
- Exclude look-alikes when you will read a password aloud or type it from paper. It removes I, l, 1, O and 0 and costs only a little entropy.
Frequently asked questions
Is this password generator safe to use?
crypto.getRandomValues). They are never sent over the network and never saved. Only your settings, such as length and character types, are remembered on this device.How long should my password be?
Is a passphrase as secure as a random password?
What does "bits of entropy" mean?
Which symbols are used?
! @ # $ % ^ * ( ) - _ = + [ ] { } ; : , . ? / ~, plus the ampersand and the less-than and greater-than signs. Quotes, backslashes, backticks and spaces are left out because some websites and command lines handle them badly.Why exclude look-alike characters?
Last updated . How we check our tools.