Password Generator

Generate a random password with your choice of length and character sets, using your browser's cryptographic random number generator. See the exact entropy in bits.

Loading tool…

Worked examples

  • A 16-character default password

    The everyday case: a strong, easy-to-type password using letters and digits for a new account signup.

  • A 24-character password with symbols for a high-value account

    Adding symbols and length increases the character set and total entropy, appropriate for a password manager master password or admin account.

  • A 6-digit numeric code

    Restricting to digits only produces a PIN-style code, useful when the receiving system only accepts numbers.

What this tool does

This tool generates a random password from the character sets you choose — lowercase letters, uppercase letters, numbers, and symbols — at a length you set, using your browser's cryptographically secure random number generator. Alongside the password, it reports the exact entropy in bits, a precise, checkable measure of how hard the password is to guess by brute force, rather than a vague "strong" or "weak" label.

When you need it

  • Creating a new account password you don't need to memorize, because it will live in a password manager.
  • Generating a strong master password for a password manager itself, where length and entropy matter most since it's the one password you do need to remember or type.
  • Producing a one-off secret — an API key placeholder, a temporary credential, a random test value — for a script or config file.
  • Generating a short numeric code when a system specifically requires digits only, by turning off the letter and symbol options.

What entropy in bits actually means

Entropy here is computed directly as length × log2(character set size) — no scoring model, no arbitrary strength meter, just the number of random guesses (as a power of two) an attacker would need on average to find this exact password by brute force, assuming they know the character set and length but not the password itself. A 16-character password using all four character sets (26 + 26 + 10 + 25 = 87 possible characters per position) has roughly 16 × log2(87) ≈ 103 bits of entropy — a number large enough that brute-forcing it is not remotely practical with any foreseeable computing power.

Because it's a direct calculation from options you control, you can reason about trade-offs precisely: doubling the length roughly doubles the entropy, while adding a character set only adds a few bits per character — length matters more than character variety once you're already using a reasonable mix.

Why no strength label

A "weak / medium / strong" meter necessarily hides a judgment call about what counts as strong enough for a given context, and different meters disagree with each other. Reporting entropy in bits instead gives you the actual number and lets you apply your own threshold: a rough, widely cited guide is 60+ bits for routine accounts and 80+ bits for high-value ones, assuming the password isn't reused anywhere else — reuse defeats any amount of entropy the moment one site is breached.

How the randomness works

Each character is chosen using crypto.getRandomValues, the Web Crypto API's cryptographically secure random source, with rejection sampling to avoid modulo bias — a subtle flaw where naively mapping random bytes onto a character set makes some characters slightly more likely than others. Nothing about the generated password is sent anywhere; it exists only in your browser for as long as the page is open.

Limits

Length ranges from 4 to 128 characters. At least one character set must be selected, or generation is refused with a clear message rather than silently producing an empty or predictable result. Because output is genuinely random, the worked examples on this page don't include a fixed expected result — run them yourself to see real generated values.

Frequently asked questions

Are generated passwords sent anywhere?
No. Passwords are generated entirely in your browser using the Web Crypto API; nothing is transmitted to a server or logged.
What is entropy and why does it matter more than a 'strength' label?
Entropy in bits measures how many random guesses an attacker would need on average — it's computed directly from length and character set size (length × log2(charset size)), so it's an exact, checkable number rather than a vague strength score.
How much entropy is enough?
As a rough guide, 60+ bits is reasonable for most accounts and 80+ bits for high-value ones, assuming the password is unique per site and not reused — a password manager makes both of those practical.
Why avoid the symbols option for some systems?
A small number of legacy forms or systems reject certain punctuation characters — turn symbols off if you hit that, and prefer more length instead to keep entropy high.