Free tools Everyday utilities

Strong passwords, generated on your device

Random passwords, memorable passphrases and PINs, drawn from your browser's cryptographically secure random number generator. Nothing is stored, logged or sent anywhere.

Password

Generated on your device with the Web Crypto API. Never stored, logged or sent.


Questions

Built by Mohd Shayan. Found a problem or have an idea? Send a note.

Is it safe to use an online password generator?

This one never sends a password anywhere: it is generated by your browser with the Web Crypto API (crypto.getRandomValues), the same source used for encryption keys, and it is not saved in the page address, in storage or in any log. You can load the page and switch off your connection before you generate, and it still works.

How long should a password be?

For accounts protected by a password manager, 16 to 20 random characters is plenty. For anything you must type or remember, a passphrase of five or six random words is easier to handle and just as hard to guess. Length matters more than symbols.

What does the strength estimate mean?

It is the entropy of the method in bits: how many guesses an attacker who knows exactly how the password was made would need. Every extra bit doubles the work. Around 70 bits or more resists offline cracking of a fast hash, and 80 bits or more is very strong. It assumes the password is used once and kept secret.

Where do the passphrase words come from?

From the EFF Long Wordlist of 7,776 short, distinct and easy-to-type English words, published by the Electronic Frontier Foundation under CC BY 3.0 US. Each word adds about 12.9 bits of entropy.

Should I reuse a strong password?

No. Use a different password for every account and keep them in a password manager. A strong password that is reused is only as safe as the weakest site that stores it.