Password Generator
A random password made in your browser and never sent anywhere, with its entropy stated in bits rather than guessed at.
Runs entirely in your browser. Nothing is uploaded, logged or stored.
- Entropy, in bits
- —
- Characters to choose from
- —
- Possible passwords
- —
- The alphabet used
- —
A random password, made by your own browser and never sent anywhere. The strength is given as entropy in bits, which is a measurement rather than an opinion, and the page explains what the number means.
How it works
Each character is drawn independently and uniformly from the alphabet you chose, using your browser's cryptographic random number generator. Nothing about the password is derived from the time, from your machine, or from anything an attacker could guess at.
The entropy is length × log2(alphabet size). That is a definition, not an estimate: it is the base-two logarithm of how many passwords your options could have produced. Every extra bit doubles that number.
It is only true of a password drawn at random, which is what this page produces and what a person choosing one does not. A password you invented has far less entropy than its length suggests, because the way people invent them is predictable.
Frequently asked questions
Is the password sent to your server?
No, and the design goes further than a promise. The server-side code on this site deliberately cannot generate a password: all it computes for this tool is the arithmetic — the alphabet, its size, the entropy — and no password at all. The only place one comes into existence is the browser that will use it.
Why is there no strength meter?
Because it would be made up. How long a password survives depends on the attacker's hardware, their budget, which hashing algorithm the site chose and how much of its database leaked. This page knows none of those, so "it would take 3 million years to crack" would be a number with nothing behind it. Entropy in bits is something that can be said truthfully.
So how many bits do I need?
More than you can remember, which is the real answer: use a password manager and the length this page offers. For a sense of scale, each bit doubles the number of possibilities, so 60 bits is a million times harder than 40. What is actually enough depends on what the password protects and on how the site stores it, neither of which is visible from here.
Why does leaving out lookalike characters lower the number?
Because it is a real trade rather than a free improvement. Removing Il1O0oB8S5Z2 makes the password easier to read off a screen and shrinks the alphabet it was drawn from, so the entropy falls. The figure moves when you tick the box, which is the point of showing it.
Is the randomness good enough?
It uses crypto.getRandomValues, the browser's cryptographic generator, rather than Math.random, which is not built for this and is predictable from its own output. If your browser has no such generator the tool says so and refuses rather than falling back to something weaker.
Good to know
- Nothing here is stored, logged or sent. There is no share link, because a password in a URL is a password in a browser history and in whatever the link was pasted into.
- The alphabet is shown alongside the figures, so you can see exactly which characters were on offer rather than trusting the count.
- Symbols are the ASCII punctuation, minus the space — which too many forms strip. Nothing else is quietly removed, because an alphabet that drops characters makes a password weaker than the figure beside it claims.