Developer Tools

Password Generator

Generate strong, cryptographically random passwords instantly. Choose length and character types, see real-time strength and entropy. Bulk generation included. 100% private: nothing sent anywhere.

Last updated · Password guidance checked against NIST SP 800-63B-4

Cryptographically Random
Entropy & Strength
Bulk Generator
100% Private
Our networkLegalCost.usWhat will your legal case cost?Official formulas for all 50 states. Free, no signup.Check your state
Password Generator
Cryptographically secure · Web Crypto API · Browser-only
Click Generate to create a password
Strength —
 
Length 16
Character Types
Uppercase
A B C … Z
Lowercase
a b c … z
Numbers
0 1 2 … 9
Symbols
! @ # $ % & *
No Ambiguous
Exclude 0 O l I 1
No Repeating
Each char once only
10 Passwords · Click any to copy

How the Generator Picks Characters

A strong password is long and random: 16 characters from this page's full 88-character set give about 103 bits of entropy, far beyond reach of any brute-force attack. Choose a length and character types above and the generator builds the password in your browser with crypto.getRandomValues, never Math.random, and shows its entropy and strength as you go.

Each character is chosen independently and uniformly from the characters you allow, using crypto.getRandomValues(), the browser's cryptographically secure random source. Values that would make some characters slightly more likely are thrown away and redrawn. Passwords are created on your device and are not sent, logged or stored.

Entropy by Length and Character Set

Entropy in bits = length × log2(pool size), for passwords picked at random. Each extra bit doubles the number of guesses an attacker needs.

LengthDigits (10)Lowercase (26)Lower + digits (36)Letters + digits (62)All types (88)
82738414852
124056627178
155071788997
1653758395103
206694103119129
2480113124143155
32106150165191207

Two things stand out. Length beats variety: 20 lowercase letters (94 bits) are stronger than 12 characters of every type (78 bits). And an 8-character password tops out at 52 bits even with symbols. The symbol set here is the 26 characters !@#$%^&*()_+-=[]{}|;:,.<>?. With No Ambiguous on, 0, O, 1, l and I are removed, so the full pool is 83 and 16 characters give 102 bits. With No Repeating on, 16 characters from 88 give 101 bits instead of 103, because each pick has one fewer option.

What the Strength Label Means

EntropyLabelExample that reaches it
Under 40 bitsWeak8 lowercase letters (38)
40 to 59 bitsFair8 characters, all types (52)
60 to 79 bitsGood12 characters, all types (78)
80 to 99 bitsStrong15 characters, all types (97)
100 to 127 bitsVery Strong16 characters, all types (103)
128 bits or moreMaximum20 characters, all types (129)

These figures hold only for randomly generated passwords. A password you make up yourself, like Summer2026!, has far less real entropy than its length suggests, because attackers try common words, dates and patterns first.

What NIST Says About Passwords

NIST SP 800-63B-4, the federal digital identity guideline finalized in 2025, sets these rules for services that accept passwords:

  • At least 15 characters when the password is the only factor, and at least 8 when it is used with multi-factor authentication.
  • Services should allow at least 64 characters, accept spaces and all printable ASCII characters, and should accept Unicode.
  • No composition rules, such as forcing a mix of character types.
  • No forced periodic changes; a change is required when there is evidence of compromise.
  • New passwords are checked against a blocklist of common, expected and breached passwords.

A site that still demands a digit and a symbol may reject a password that lacks one by chance. If that happens, generate again; with all types on, about 84% of 16-character passwords include every type, and the one missing is usually a digit. For other secrets, such as random IDs, the UUID generator uses the same secure random source.

Method and sources. Entropy = length × log2(pool), and log2(pool × (pool − 1) × ...) for No Repeating; every value in the tables was computed in Node.js and matches what the tool shows. Password rules: NIST SP 800-63B-4, Digital Identity Guidelines, Authentication and Authenticator Management (2025). Random source: W3C Web Cryptography API, getRandomValues.

Password Security Guide

Yes. This generator uses your browser's built-in crypto.getRandomValues() API, which is cryptographically secure and produces truly unpredictable output. No password is sent to any server, logged, or stored anywhere. Everything runs locally in your browser. You can disconnect from the internet after the page loads and the tool will continue to work. The source code is visible: right-click the page and inspect it to verify yourself.

For most accounts: 16 characters minimum. For sensitive accounts like banking, email, or work systems: 20 or more characters. Length matters more than complexity. A random 20-character lowercase-only password is mathematically stronger than a complex 8-character one. Our default of 16 characters with all character types produces about 103 bits of entropy, enough to resist any realistic brute-force attack for billions of years.

Entropy measures unpredictability in bits. Formula: bits = log2(pool_size) × length. With all character types enabled: on this page the pool is 88 characters (26 uppercase, 26 lowercase, 10 digits, 26 symbols), and log2(88) ≈ 6.46 bits per character. A 16-character password: 6.46 × 16 ≈ 103 bits. Each additional bit doubles the difficulty to crack. Under 40 bits is weak, 60 to 80 is decent for low-risk accounts, 100+ is strong, 128+ is overkill for most use cases. Entropy drops when you exclude character types or enable no-repeating (which reduces the pool as characters are used).

Yes, always. A password manager (Bitwarden is free and open-source, 1Password and Dashlane are excellent paid options, KeePass for offline use) lets you use a unique, complex password for every account without memorizing any of them. Credential stuffing, where an attacker uses leaked passwords from one site to break into others, is one of the most common attack vectors. A password manager completely eliminates this risk. Use a strong master password and enable two-factor authentication on the manager itself.

Ambiguous characters are those that look identical or very similar depending on the font: 0 (zero) and O (capital O), 1 (one), l (lowercase L), and I (uppercase i). Enable "No Ambiguous" when you need to type the password by hand: on a TV, gaming console, ATM, or any device where you cannot paste. It slightly reduces entropy (removes exactly 5 characters from the pool, 88 down to 83 with every type on) but prevents frustrating misreads.

Two-factor authentication (2FA) adds a second verification step beyond your password: a time-based code from an app (Google Authenticator, Authy), an SMS code, a hardware key (YubiKey), or a biometric. Even if your password is compromised, an attacker cannot access your account without the second factor. Always enable 2FA on critical accounts: email, banking, password manager, work systems, and any account with payment information. An authenticator app is more secure than SMS, which is vulnerable to SIM-swapping attacks.

A passphrase is a sequence of random words: for example "correct-horse-battery-staple" (from the famous xkcd comic). Four random words from a 7,776-word list (Diceware) give approximately 51 bits of entropy. Five words give 64 bits. Six words give 77 bits. Passphrases are easier to memorize than random character strings and can be typed without a password manager. However, a 16-character random password with full character types still offers more entropy (103 bits) than a 5-word passphrase. Both approaches are valid. Use passphrases for accounts you need to type by memory, random passwords for everything stored in a manager.

Modern guidance from NIST (the US standards body) no longer recommends regular mandatory password changes. Frequent rotation causes people to choose weaker, predictable passwords (Password1, Password2...). You should change a password when: you know or suspect it has been compromised, a service you use reports a data breach (check haveibeenpwned.com), or you have shared it with someone. Strong, unique passwords that are not reused are the priority. If you are reusing passwords across sites, stop immediately: generate a new unique password for each account and store them in a password manager.

crypto.getRandomValues() is a browser-native API that fills an array with cryptographically secure random numbers using the operating system's entropy sources (hardware events, thermal noise, etc.). It is fundamentally different from Math.random(), which is a pseudo-random number generator designed for speed, not security. Math.random() output is predictable if the attacker knows the seed. crypto.getRandomValues() output is computationally indistinguishable from true randomness. This tool exclusively uses the secure API. Never use Math.random() for anything security-related.

Yes, with one exception: your password manager's master password. That one you need to memorize, since it is not stored anywhere. For the master password, use a long passphrase (6+ random words) that you can remember and type. Use a 24+ character random password generated here as your master password only if you are certain you can remember it or have a secure offline backup. For every other account, let your password manager store the generated password and never reuse it. The single most impactful security action most people can take is switching from reused passwords to unique ones managed in a password manager.

For an online account protected by rate limiting, 60 bits or more is hard to guess. For anything that could be attacked offline after a breach, such as a password manager vault or an encryption key, aim for 80 to 100 bits or more. A random 16-character password with all character types (103 bits) covers both. Entropy only counts for randomly generated passwords, not for ones people make up.

Length usually wins. Going from letters and digits (62 characters) to all types (88) adds about half a bit per character, while every extra character adds 5.95 to 6.46 bits. 12 characters with symbols give 78 bits; 16 characters of letters and digits give 95 bits. Use symbols when a site allows them, but make the password longer first.