Strong Password Generator
Create a strong, random password in one click. It is generated on your own device with your browser's cryptographic random number generator, and it is never sent to us or stored.
More options with the same settings
How to use the generator
- Set the length. 16 characters or more is a good default. Use 20 or more for email, banking and your password manager.
- Choose the character types. Keep all four switched on unless a website rejects certain symbols.
- Press Copy and paste the password straight into the sign-up form and into your password manager.
- Do not reuse it. Generate a different password for every account.
Turn on Avoid look-alikes if you will ever have to read the password aloud or type it by hand, for example a Wi-Fi password. It removes characters that are easy to confuse, such as capital O and zero.
What makes a password strong
Strength comes from two things: how long the password is and how random it is. Each extra random character multiplies the number of possible passwords an attacker has to try. The meter above shows this as bits of entropy. Every additional bit doubles the work.
| Length | Lower-case only | Letters + digits | All four types |
|---|---|---|---|
| 8 | 38 bits | 48 bits | 51 bits |
| 12 | 56 bits | 71 bits | 77 bits |
| 16 | 75 bits | 95 bits | 103 bits |
| 20 | 94 bits | 119 bits | 129 bits |
| 24 | 113 bits | 143 bits | 154 bits |
Two things stand out. A 16-character lower-case password is stronger than an 8-character one with every symbol on the keyboard, so length matters more than complexity. And these figures only hold for truly random passwords. A word with a number on the end has far less entropy than its length suggests, because attackers try common patterns first.
As a guide, under about 50 bits is weak, 75 bits or more is strong for everyday accounts, and 100 bits or more is beyond any realistic guessing attack.
Is it safe to use an online password generator?
It depends on how the generator works. This one is safe for three reasons:
- It runs in your browser. The password is created by code on this page, on your device. It is not requested from a server and is not transmitted anywhere.
- It uses a cryptographic random source. The page calls the browser's built-in secure random number generator, the same one used for encryption keys, and avoids the predictable
Math.randomfunction. - Nothing is saved. The password is not written to storage or to the web address. Reload the page and it is gone.
Good habits still apply. Use a device you trust, and store the password in a password manager rather than a note or a text file. Most password managers and browsers also have a generator built in, which fills the password in for you. Use whichever is most convenient; the important part is that every password is long, random and unique.
After you generate a password
- Save it in a password manager. Nobody can remember dozens of random passwords, and you should not try.
- Turn on two-step verification wherever it is offered, especially for email, which is the key to resetting everything else.
- Use passkeys where a site supports them. They replace the password entirely and cannot be phished.
- Change a password when there is a reason, such as a breach notice or a suspicious login. Routine changes on a schedule are no longer recommended.
For the full picture, read how to create a strong password. For novelty text rather than security, see the hacker text generator, and note that leet-style swaps do not make a password strong.
Password generator FAQ
How long should a strong password be?
At least 16 random characters for ordinary accounts, and 20 or more for email, banking and your password manager's master password.
Are the generated passwords stored or sent anywhere?
No. Passwords are created in your browser and are not sent to any server, saved, or added to the page address.
Is this password generator really random?
Yes. It uses the browser's cryptographically secure random number generator and an unbiased selection method, so every allowed character is equally likely in every position.
What if a website does not accept symbols?
Untick Symbols and increase the length by a few characters to keep the same strength.
Should I use the same strong password everywhere?
No. If one site is breached, attackers try the leaked password on other sites. Use a different password for every account.
More tools
- Hacker Text GeneratorLeet speak and glitch text to copy and paste.
- Binary TranslatorTranslate text to binary, hex or decimal and back.
- Hacker TyperThe classic: mash any key, get lines of kernel code.
- Hacker SimulatorA full fake hacking dashboard with one click.
- Fake Update ScreenWindows, Mac and more: an update that never finishes.
- Matrix RainFalling green code with colour, speed and size controls.
- White ScreenPure white for light, tracing and pixel checks.