Password Generator

Strong random passwords, generated in your browser

chars

Enter a length (8-64)

Your Password
--
--
Strength
--
Entropy
--
Character Pool
--
Offline Crack Time

Password Generator — Complete Guide

Most passwords are cracked, not guessed. Attack programs try billions of combinations per second against leaked password databases, and they start with the patterns humans love — names, years, substitutions like "a" → "@". The only reliable defence is length plus genuine randomness, which is exactly what this generator produces.

What this generator does

Choose a length between 8 and 64 characters, tick the character types you want — uppercase, lowercase, digits, symbols — and optionally exclude lookalikes such as I, l, 1, O and 0. Every press of the button draws characters with crypto.getRandomValues(), your browser's cryptographic random number generator, so the result is unpredictable even to someone who knows every option you picked.

How strength is measured

entropy (bits) = length × log₂(pool size) guesses needed ≈ 2^entropy ÷ 2 offline crack time ≈ guesses ÷ 10¹¹ per second

The pool is the total number of distinct characters allowed. All four sets gives 94 characters before exclusions, so log₂(94) ≈ 6.55 bits per character — a 16-character password carries about 105 bits. The crack-time estimate assumes an offline attack at 100 billion guesses per second, roughly the speed of a serious GPU rig against a stolen hash file.

What the numbers look like

LengthPoolEntropyOffline crack time
89452 bitshours–days
129479 bitsmillions of years
1694105 bitsbillions of years

Using it well

One reassurance about this page: it is a static file with no server and no analytics on the inputs. Generate a password with your network disconnected if you want proof — it works exactly the same.

Frequently Asked Questions

What makes a password strong?

Length and randomness. Every extra character multiplies the work an attacker must do, and true randomness removes patterns that cracking software exploits. A 16-character random password mixing all four character types has about 100 bits of entropy — far beyond practical offline cracking.

Are passwords generated here safe to use?

Yes. They are produced locally by crypto.getRandomValues(), the browser's cryptographic random number generator, and never sent anywhere — there is no server involved. The page is a static file you can even disconnect from the network and keep using.

Should I exclude ambiguous characters like I, l and 0?

Only if you will type the password by hand from a printed copy, where I/l/1 and O/0 are easy to confuse. When a password manager fills it in automatically, keeping those characters makes the pool larger and each character slightly harder to guess.

Last reviewed: October 5, 2026 · How we calculate · Sources: NIST SP 800-63B