How the Generator Picks Characters
A strong password is long and random: 16 characters from this page's full 88-character set give about 103 bits of entropy, far beyond reach of any brute-force attack. Choose a length and character types above and the generator builds the password in your browser with crypto.getRandomValues, never Math.random, and shows its entropy and strength as you go.
Each character is chosen independently and uniformly from the characters you allow, using crypto.getRandomValues(), the browser's cryptographically secure random source. Values that would make some characters slightly more likely are thrown away and redrawn. Passwords are created on your device and are not sent, logged or stored.
Entropy by Length and Character Set
Entropy in bits = length × log2(pool size), for passwords picked at random. Each extra bit doubles the number of guesses an attacker needs.
| Length | Digits (10) | Lowercase (26) | Lower + digits (36) | Letters + digits (62) | All types (88) |
|---|---|---|---|---|---|
| 8 | 27 | 38 | 41 | 48 | 52 |
| 12 | 40 | 56 | 62 | 71 | 78 |
| 15 | 50 | 71 | 78 | 89 | 97 |
| 16 | 53 | 75 | 83 | 95 | 103 |
| 20 | 66 | 94 | 103 | 119 | 129 |
| 24 | 80 | 113 | 124 | 143 | 155 |
| 32 | 106 | 150 | 165 | 191 | 207 |
Two things stand out. Length beats variety: 20 lowercase letters (94 bits) are stronger than 12 characters of every type (78 bits). And an 8-character password tops out at 52 bits even with symbols. The symbol set here is the 26 characters !@#$%^&*()_+-=[]{}|;:,.<>?. With No Ambiguous on, 0, O, 1, l and I are removed, so the full pool is 83 and 16 characters give 102 bits. With No Repeating on, 16 characters from 88 give 101 bits instead of 103, because each pick has one fewer option.
What the Strength Label Means
| Entropy | Label | Example that reaches it |
|---|---|---|
| Under 40 bits | Weak | 8 lowercase letters (38) |
| 40 to 59 bits | Fair | 8 characters, all types (52) |
| 60 to 79 bits | Good | 12 characters, all types (78) |
| 80 to 99 bits | Strong | 15 characters, all types (97) |
| 100 to 127 bits | Very Strong | 16 characters, all types (103) |
| 128 bits or more | Maximum | 20 characters, all types (129) |
These figures hold only for randomly generated passwords. A password you make up yourself, like Summer2026!, has far less real entropy than its length suggests, because attackers try common words, dates and patterns first.
What NIST Says About Passwords
NIST SP 800-63B-4, the federal digital identity guideline finalized in 2025, sets these rules for services that accept passwords:
- At least 15 characters when the password is the only factor, and at least 8 when it is used with multi-factor authentication.
- Services should allow at least 64 characters, accept spaces and all printable ASCII characters, and should accept Unicode.
- No composition rules, such as forcing a mix of character types.
- No forced periodic changes; a change is required when there is evidence of compromise.
- New passwords are checked against a blocklist of common, expected and breached passwords.
A site that still demands a digit and a symbol may reject a password that lacks one by chance. If that happens, generate again; with all types on, about 84% of 16-character passwords include every type, and the one missing is usually a digit. For other secrets, such as random IDs, the UUID generator uses the same secure random source.
Password Security Guide
crypto.getRandomValues() API, which is cryptographically secure and produces truly unpredictable output. No password is sent to any server, logged, or stored anywhere. Everything runs locally in your browser. You can disconnect from the internet after the page loads and the tool will continue to work. The source code is visible: right-click the page and inspect it to verify yourself.bits = log2(pool_size) × length. With all character types enabled: on this page the pool is 88 characters (26 uppercase, 26 lowercase, 10 digits, 26 symbols), and log2(88) ≈ 6.46 bits per character. A 16-character password: 6.46 × 16 ≈ 103 bits. Each additional bit doubles the difficulty to crack. Under 40 bits is weak, 60 to 80 is decent for low-risk accounts, 100+ is strong, 128+ is overkill for most use cases. Entropy drops when you exclude character types or enable no-repeating (which reduces the pool as characters are used).0 (zero) and O (capital O), 1 (one), l (lowercase L), and I (uppercase i). Enable "No Ambiguous" when you need to type the password by hand: on a TV, gaming console, ATM, or any device where you cannot paste. It slightly reduces entropy (removes exactly 5 characters from the pool, 88 down to 83 with every type on) but prevents frustrating misreads.crypto.getRandomValues() is a browser-native API that fills an array with cryptographically secure random numbers using the operating system's entropy sources (hardware events, thermal noise, etc.). It is fundamentally different from Math.random(), which is a pseudo-random number generator designed for speed, not security. Math.random() output is predictable if the attacker knows the seed. crypto.getRandomValues() output is computationally indistinguishable from true randomness. This tool exclusively uses the secure API. Never use Math.random() for anything security-related.