Skip to main content
Security Tool Client-Side Only

Random Password Generator

Create strong and secure passwords instantly

Generated Password Password

Password Length: 16
664

Character Options
Password Best Practices
  • Use at least 12 characters for strong protection
  • Include a mix of uppercase, lowercase, numbers, and symbols
  • Never reuse passwords across different accounts
  • Change passwords regularly, especially for sensitive accounts
  • Use a password manager to store passwords securely
Frequently Asked Questions

How does the password generator work?

Our password generator uses cryptographically secure random number generation to create unpredictable passwords based on your selected criteria.

Is it safe to use this password generator?

Yes, all passwords are generated entirely in your browser. Nothing is sent to our servers, ensuring complete privacy.

What makes a password strong?

A strong password is long (12+ characters), complex (mixed character types), and unique for each account.

How often should I change my passwords?

Change passwords every 3-6 months for sensitive accounts, or immediately if you suspect a breach.

Expert guide · Password Generator

What it does

The Password Generator builds random passwords between 6 and 64 characters from the character classes you enable: uppercase, lowercase, digits and 26 symbols, for a pool of up to 88 characters. Each character is chosen with crypto.getRandomValues, the browser's cryptographically secure random number generator, and everything happens locally: the password is never sent to a server and the short history of your last five results lives only in the open page.

Why it matters

  • Credential stuffing defense: Reused passwords are replayed from old breaches against every major login; a unique random password per site makes each leak a dead end.
  • Human choices are predictable: Patterns like Summer2026! satisfy complexity rules yet appear in the first minutes of any cracking wordlist.
  • Service and API accounts: Database users, Wi-Fi PSKs and router admin accounts deserve 20+ random characters because nobody needs to type them often.
  • Offline cracking resistance: If a site stores hashes poorly, only high-entropy passwords survive a GPU attack on the leaked database.
  • Quick, private generation: Admins can create a strong temporary credential during an incident without installing software or trusting a remote service.

How to read the results

  • Length slider: 6 to 64 characters, default 16. Each extra character multiplies the search space by the pool size, so length is the most effective setting.
  • Character options: Uppercase (26), lowercase (26), numbers (10) and symbols !@#$%^&*()_+-=[]{}|;:,.<>? (26). Disable symbols only when a system rejects them, and compensate with extra length.
  • Strength label: A quick heuristic based on length and enabled classes, from Very Weak to Very Strong. For a precise figure, compute entropy as length times log2(pool size).
  • Entropy reference: 16 characters from all 88 symbols is about 103 bits; 20 characters of letters and digits (62) is about 119 bits; anything above 80 bits is beyond realistic offline attack.
  • History list: The last five passwords generated in this session, kept only in page memory and lost on reload; copy the one you use into a password manager immediately.

Technical background

Password strength is best measured as entropy: the number of bits an attacker must search when they know exactly how the password was generated. For a uniformly random password the formula is length × log2(charset size). A 12-character password using only lowercase letters gives 12 × 4.70 ≈ 56 bits; 16 characters from this tool's full 88-character pool gives 16 × 6.46 ≈ 103 bits. Each bit doubles the work, so length dominates: adding four characters to a lowercase password adds about 19 bits, while switching from lowercase to the full pool on the same length adds 1.76 bits per character. Entropy applies only to truly random output; a human-chosen P@ssw0rd2026 has far less than its length suggests.

Randomness quality is therefore essential. This generator fills a Uint32Array with crypto.getRandomValues, which the Web Crypto specification requires to come from a cryptographically secure source seeded by the operating system, and maps each value onto the selected pool with a modulo operation. With 32-bit values and a pool of at most 88 symbols, the resulting bias is below one part in forty million per character, negligible for practical purposes. Never use Math.random for secrets; it is a fast but predictable PRNG.

NIST SP 800-63B, finalized as Revision 4 in 2025, reshaped password policy around evidence. Verifiers should prioritize length (at least 15 characters when a password is the only authentication factor, 8 when used with MFA) and accept at least 64 characters; must not impose composition rules such as one uppercase plus one symbol; must not force periodic expiration, only a change when compromise is suspected; and must screen new passwords against blocklists of breached, common and context-specific values. Long random strings generated here satisfy those rules easily, and a password manager removes the memorization burden.

When a password must be typed or remembered, such as a manager's master password or a disk encryption passphrase, a passphrase of randomly selected words is the better format. With a 7,776-word diceware list each word adds log2(7776) ≈ 12.9 bits, so six words reach about 77 bits and seven about 90, while remaining easy to type on a phone. Whatever the format, the strongest password still fails if phished, so pair important accounts with phishing-resistant MFA such as passkeys or FIDO2 security keys.

Common errors and how to fix them

Problem A website rejects the generated password because of a symbol.
Fix Some legacy systems block characters such as < > ; or quotes. Disable symbols and increase length by four to six characters to keep the same or higher entropy.
Problem Short passwords that look complex.
Fix An 8-character password from all 88 symbols has only about 52 bits of entropy, within reach of GPU cracking if a fast hash leaks. Use 16 or more characters for accounts and 20+ for service credentials.
Problem Forcing users to rotate passwords every 90 days.
Fix NIST SP 800-63B advises against periodic rotation because it drives predictable increments (Password1, Password2). Require a change only on evidence of compromise and check new passwords against breach blocklists.
Problem Reusing one strong generated password across several sites.
Fix Strength does not help if another site leaks it in plaintext or with a fast hash. Generate a unique password per service and store them in a password manager.
Problem Copying the password into a chat, ticket or spreadsheet.
Fix Store it directly in a password manager or secrets vault, and share credentials through the vault's sharing feature or a one-time secret link. Rotate any password that was posted in plaintext.

Do it from the command line

macOS

# 24 random bytes as Base64 (about 32 characters, 192 bits)
openssl rand -base64 24
# 20 alphanumeric characters from the kernel CSPRNG
LC_ALL=C tr -dc 'A-Za-z0-9' < /dev/urandom | head -c 20; echo

Windows

# PowerShell: 18 bytes from the system CSPRNG, Base64-encoded
$b = New-Object byte[] 18; [Security.Cryptography.RandomNumberGenerator]::Create().GetBytes($b); [Convert]::ToBase64String($b)
# OpenSSL from Git for Windows works too
openssl rand -base64 24

Linux

# Fully random 20-character password
pwgen -s 20 1
# Same without extra packages
tr -dc 'A-Za-z0-9!@#%^*_+=' < /dev/urandom | head -c 20; echo
# Six-word passphrase from a local wordlist
shuf --random-source=/dev/urandom -n 6 /usr/share/dict/words | tr '\n' '-'; echo

More questions about Password Generator

How long should a password be in 2026?

For accounts protected only by a password, at least 15 characters, which matches the minimum in NIST SP 800-63B Revision 4. Generated passwords stored in a manager can easily be 20 characters or more. Sixteen random characters from letters, digits and symbols give about 103 bits of entropy, far beyond what offline cracking can reach.

Is this password generator safe to use?

Yes. The password is produced in your browser with crypto.getRandomValues, the operating-system-backed secure random source, and is never transmitted. You can disconnect from the network after the page loads and it still works. The recent-password history is kept only in page memory and disappears when you reload or close the tab.

How do I calculate password entropy?

Multiply the length by log2 of the number of possible characters. Lowercase only is 26 symbols or 4.7 bits each; letters and digits are 62 or 5.95 bits; this tool's full set is 88 or 6.46 bits. So 16 characters from the full set is roughly 103 bits. The formula only holds for randomly generated passwords.

Are passphrases better than random passwords?

For anything you must memorize or type, yes. Six words chosen randomly from a 7,776-word diceware list give about 77 bits and are much easier to remember than 13 random symbols of similar strength. For credentials kept in a password manager, a long random string is simpler and stronger.

Should I still change my passwords every few months?

Current NIST guidance says no. Forced periodic rotation pushes people toward predictable variations and does not stop modern attacks. Change a password when there is evidence it was exposed, such as a breach notification or phishing, and focus on unique passwords per site plus multi-factor authentication.

100-Day Max Lifespan
155d 5h 19m 59s
PQC Migration Target
1178d 5h 19m 59s