Password generator
Choose the length and which characters to include, and the passwords are made in your browser.
Characters
Without 0, O, o, 1, I, l and |.
Password
Strength
Very strong
- Entropy in bits129
- Character set87 characters
- Possible passwords6.2 × 1038
The scale is a guide, not a promise. Below 50 bits is crackable by anyone who really wants to, and 128 bits is beyond anything that can be built.
More to choose from
All made with the same settings.
Everything is made in your browser. Nothing is stored and nothing is sent anywhere.
How it works
The randomness comes from the browser’s cryptographic source, which exists precisely for values that must be impossible to guess. The ordinary random function in JavaScript will not do: it is predictable to anyone who has seen enough of its output.
Each character is drawn evenly from the chosen set. A plain remainder would favour the lowest values when the set does not divide evenly, so the topmost draws are thrown away and redrawn.
Entropy measures how many guesses are needed, expressed as a power of two. It applies to passwords drawn this way. A password you thought up yourself almost always has less entropy than its length suggests, because language and keyboards steer the choices more than people realise.
Length matters more than the character set. Going from twelve to sixteen characters buys more than adding symbols does, and it is easier to type.
The option to avoid lookalikes removes zero, capital O and lowercase o, one, capital I, lowercase l and the vertical bar. It costs a little entropy but is worth it when the password has to be read aloud or typed in by hand on another device, such as a TV or a games console.
Nothing made here leaves your browser, and the page stores nothing. Close the tab and the passwords are gone.
How the tool works
The character set is built from the groups you choose: 26 lower-case letters, 26 capitals, 10 digits and 25 symbols, 87 in all. Avoiding lookalikes removes seven of them and leaves 80. Each character is drawn separately with crypto.getRandomValues. A 32-bit random number has 4,294,967,296 possible values, and the top 16 are thrown away and redrawn, so that the rest divide exactly by 87 and every character is equally likely.
Entropy is the length times the base-2 logarithm of the set size. Twenty characters from 87 give 20 × 6.443 = 128.86 bits, which the tool shows as 129. Without lookalikes it is 20 × 6.322 = 126.4 bits. The scale under the result calls anything under 50 bits weak, under 75 fair, under 110 strong and the rest very strong.
Length or symbols
With the tool’s own figures: 12 characters from all 87 give 77 bits, 16 characters without symbols, so from 62, give 95 bits, and 16 characters with symbols 103 bits. The four extra characters add 26 bits, the symbols 8.
What the authorities advise
The UK National Cyber Security Centre recommends combining three random words into a password that is long enough and strong enough, says the long-standing advice to make passwords very complex is not helpful, because few people can memorise many complex passwords, and points to password managers, which can create strong passwords and remember them. In the United States, NIST SP 800-63B, revision 4 of July 2025, says services must require at least 15 characters when the password is the only factor and at least 8 alongside another factor, should allow at least 64, must allow password managers, and must not demand mixed character types or periodic changes. The tool’s lengths run from 6 to 64.
Edge cases
The tool does not guarantee that every chosen group appears in the password. With all four groups, roughly one 20-character password in eleven lacks at least one of them, and at 8 characters 51% do. A service that insists on a digit, say, may then refuse the password. If so, generate a new one rather than swap a character by hand. Discarding passwords that lack a group costs only 0.14 bits at 20 characters, but a character you pick yourself is not random at all.