All tools run in your browser — your files never leave your device.
All tools154

Utilities & Converters

Password Generator

Cryptographically random passwords with a live entropy meter.

What it does. A password generator produces random strings that resist guessing. This tool uses <code>crypto.getRandomValues</code> — the browser’s cryptographically secure random source — rather than <code>Math.random</code>, shows live entropy in bits, and estimates offline crack time. Nothing is generated on or sent to a server.
Runs in your browserNothing uploadsNo signupWorks offline

How to use Password Generator

  1. Set the length and choose which character sets to include, or switch to passphrase mode.
  2. Read the entropy in bits and the estimated crack time.
  3. Copy the password. It is generated locally and never transmitted.

How long should a password be?

Length beats complexity. Each additional character multiplies the search space; adding a symbol to a short password barely moves it.

How long should a password be?
LengthCharacter setEntropyOffline crack time (10¹² guesses/sec)
8lower + digits41 bits~35 minutes
8all 94 printable52 bits~2 months
12all 94 printable79 bits~19 million years
16all 94 printable105 bitseffectively forever
4 wordsdiceware list52 bits~2 months
6 wordsdiceware list78 bits~9 million years
7 wordsdiceware list90 bitseffectively forever

The practical recommendation for 2026: 16 characters minimum for anything you type rarely and store in a manager, or a 6-word passphrase for anything you must type by hand — a device login, a password manager master password, a disk encryption key.

What is entropy and why does it matter?

Entropy measures how many guesses an attacker needs, expressed in bits. Each bit doubles the search space, so 60 bits is not twice as strong as 30 bits — it is a billion times stronger.

It is calculated as log₂(pool size) × length. A 12-character password from the 94 printable ASCII characters gives log₂(94) × 12 ≈ 78.7 bits.

The critical condition is that the password must actually be random. "P@ssw0rd123!" has 12 characters from a 94-character pool, which naively computes as 78 bits — but it is in every cracking dictionary and falls in under a second. Entropy only counts if the selection was genuinely random, which is exactly what a generator provides and a human choosing a memorable password does not.

Are passphrases better than random passwords?

For anything you have to type from memory, yes. For anything stored in a password manager, it makes no difference.

A passphrase built from randomly selected dictionary words — the Diceware method — gets its entropy from the word list size, not the character count. A 7,776-word list gives 12.9 bits per word, so six words is 77.5 bits: comparable to a 12-character random password, and vastly easier to remember and type on a phone or a TV remote.

The requirement is that the words be chosen randomly by the generator. Picking six words yourself produces something close to a sentence, and human-chosen word sequences follow predictable patterns that cut the effective entropy by more than half.

The XKCD "correct horse battery staple" example is four words at 44 bits, which was reasonable in 2011 and is marginal now. Use six.

Why does Math.random() matter?

Because it is not random enough for anything security-relevant, and a surprising number of online password generators use it.

Math.random() is a pseudorandom number generator optimized for speed. In V8 it uses xorshift128+, seeded from a limited entropy source, and its internal state can be recovered from a modest number of observed outputs. Given a few generated values, an attacker can predict every subsequent one.

crypto.getRandomValues() draws from the operating system’s cryptographically secure entropy pool — /dev/urandom on Unix, BCryptGenRandom on Windows — which is designed to be unpredictable even to an adversary who has seen prior output.

This tool uses the latter, with rejection sampling to avoid the modulo bias that would otherwise make some characters marginally more likely than others. It is a small detail, and it is the difference between a uniform distribution and a slightly skewed one.

Frequently asked questions

Is it safe to generate a password on a website?

On this one, yes, because generation happens in your browser with Web Crypto and nothing is transmitted. Verify it yourself in the Network tab. A generator that produces passwords on a server is a category of tool to avoid.

Should I use symbols?

They help, but less than length. Adding four characters to the length increases entropy more than adding the full symbol set to a short password. Some systems also reject certain symbols, which is its own annoyance.

How often should I change my passwords?

Only when there is reason to — a breach, a shared credential, or a suspicion of compromise. NIST withdrew the routine-expiry recommendation in 2017, because forced rotation pushes people toward predictable incremental changes.

What is the strongest password length?

16 characters random, or 6 words as a passphrase, both comfortably exceed what is brute-forceable. Beyond that you are protecting against nothing that exists.

Do I need a different password for every site?

Yes, and this is more important than length. Credential stuffing — replaying a password leaked from one breach against every other service — is the most common account compromise route by a wide margin.

Are the generated passwords stored?

No. They exist in the page memory until you navigate away. Nothing is logged, saved or transmitted.

What is a password manager and do I need one?

Software that stores unique passwords behind one master password. Yes — it is the only practical way to have a different strong password everywhere. Use a passphrase for the master password.

Guides for Password Generator