About the Password Generator
The strongest passwords are ones no person would ever think of: long, random strings of letters, numbers and symbols. People are poor at making them up — we fall back on words, names, dates and patterns that attackers guess first. A password generator removes that weakness by choosing every character at random.
This password generator creates strong random passwords of any length from 4 to 128 characters, using any combination of lowercase and uppercase letters, digits and symbols. It can leave out look-alike characters that are easy to misread, can make up to 20 passwords at once, and shows each password's strength in bits. Passwords are generated in your browser with its cryptographic random generator and are never sent or stored.
How to Use the Password Generator
Choose the length. Use at least 12 characters for everyday accounts and 16 or more for important ones.
Tick the kinds of character to include: lowercase, uppercase, digits and symbols.
Tick leave out look-alikes if you may need to read or type the password by hand.
Choose how many passwords to generate, and press Calculate. Press it again for new passwords.
How the Passwords Are Made
pool = lowercase (26) + uppercase (26) + digits (10) + symbols (13)
strength = length × log2(pool) bits
The generator picks one character from each type you choose, fills the rest of the length from the whole pool, then shuffles the positions. That guarantees every chosen type appears — so the password satisfies rules such as "must contain a number" — without always putting the digit or symbol in the same place. Every character is chosen with the browser's cryptographic random generator, the same kind used to create encryption keys.
Step-by-Step Example
16 characters with all four kinds.
Pool: 26 + 26 + 10 + 13 = 75 characters
Strength: 16 × log2(75) = 16 × 6.23 = about 100 bits
16 characters without look-alikes (O, 0, I, l and 1).
Pool: 75 − 5 = 70 characters
Strength: 16 × log2(70) = about 98 bits
How Strong Is Strong Enough?
Every bit of entropy doubles the number of guesses needed. At 60 bits, a password would take an attacker making 10 billion guesses a second nearly two years on average to find by brute force. At 80 bits it would take millions of years, and at 100 bits the number is far beyond any foreseeable computing power. For most accounts, 16 random characters from a mixed pool are more than enough; longer passwords are useful for encryption keys and password manager master passwords.
Why the Generator Never Uses a Seed
Other random tools on this site let you enter a seed to repeat a result. The password generator deliberately does not: a password that can be reproduced from a seed is only as secret as the seed. Every password here comes fresh from the browser's cryptographic random source, so it cannot be recreated by anyone else, including us.
Storing Your Passwords
Random passwords are hard to remember, which is exactly what makes them strong. The practical way to use them is with a password manager, which stores them securely, fills them in for you, and can generate them too. Protect the manager with a long passphrase you can remember and two-factor authentication. Avoid writing passwords in plain text files, emails or notes apps without encryption.
Symbols and Website Rules
Some websites reject certain symbols or limit length. The symbols offered here — ! @ # $ % ^ & * - _ = + ? — are accepted by most sites. If a site rejects a password, try again without symbols and add a few extra characters to make up the strength: each additional character adds about six bits.
Passphrases as an Alternative
Where a password must be typed or remembered — a computer login, a password manager's master password, or a Wi-Fi password shared with guests — a passphrase of several random words can be easier to use than a string of symbols. Six words chosen at random from a list of 7,776 give about 78 bits of entropy, comparable to a 13-character random password. The key is that the words are chosen randomly, for example by rolling dice, not picked by hand.
Changing Passwords
Current security advice is not to change strong, unique passwords on a fixed schedule, because forced changes lead people to choose weaker, predictable passwords. Change a password when there is a reason: a data breach at the service, signs someone else has used the account, or if you shared it and no longer want that person to have access. When you do change it, generate a completely new one rather than altering the old one slightly.
Sharing a Password Safely
If you must share a password, use your password manager's secure sharing feature or send it through a different channel from the username, and change it afterwards.
Understanding Your Result
Password shows the generated passwords, separated by two spaces.
Strength gives the bits of entropy, the length and the pool size.
Characters used lists the kinds of character included.
Rating describes the strength against guessing.
Privacy explains that everything happens in your browser.
When Should You Use This Calculator?
Creating a new account.
Changing a password after a data breach.
Setting up Wi-Fi or device passwords.
Generating API keys or test credentials.
Filling a password manager with unique passwords.
Common Mistakes
Choosing a short length to make it easier to type.
Reusing a generated password on several sites.
Saving passwords in a plain text file.
Leaving out every symbol and digit without adding length.
Emailing a password to yourself.