Password generator

Pick a length and the character types to include, then press Generate. The password is created on your device with the browser's secure random generator and never leaves it.

4 to 128 characters. 16 or more is recommended for important accounts.

Result

Your password
2qEG@WZPyK(P-[EW
Entropy
103.9 bits
Strength
Very strong
Time to crack (10 billion guesses per second)
about 29.4 trillion years
Try an example:

How to use this tool

  1. Choose a length; 16 characters or more is a good default.
  2. Tick the character types your service allows. Keeping all four gives the strongest result.
  3. Turn on "Exclude look-alike characters" if you will type the password by hand.
  4. Press Generate, copy the password and store it in a password manager.

Good to know

  • Symbols used: !@#$%^&*()-_=+[]{};:,.<>?/|~ (28 characters); some services allow only a subset.
  • Crack-time estimates assume 10 billion guesses per second and half of the keyspace searched.

Frequently asked questions

How is the entropy calculated?

Entropy is length × log₂(alphabet size), measured in bits. With all four character types the alphabet has 90 characters, so a 16-character password has 16 × 6.49 ≈ 104 bits. Each extra bit doubles the number of guesses an attacker needs, which is why length matters more than any single symbol.

What do the strength labels mean?

Weak is under 40 bits, Fair under 60, Strong under 80 and Very strong 80 bits or more. Around 60 bits resists online guessing comfortably; 80 bits or more holds up against offline attacks on stolen password databases. The labels assume the password is random, not a dictionary word with substitutions.

How is the time to crack estimated?

The estimate assumes an attacker trying 10 billion guesses per second, roughly a strong GPU rig against a fast hash, and needing on average half of all possible combinations. Real speeds vary enormously: a slow hash such as bcrypt makes it far longer, while a leaked plaintext password makes it zero.

Does the password always contain every selected type?

Yes. One character is drawn from each selected type first, the rest are drawn from the combined alphabet, and the result is shuffled. That guarantees the password passes rules such as "at least one digit and one symbol" without making any position predictable, even at the minimum length of four.

Is it safe to generate passwords on a website?

This page runs entirely in your browser using crypto.getRandomValues; nothing is sent to a server or stored. Even so, the safest habit is to paste the password straight into a password manager, use a different password for every account and turn on two-factor authentication wherever it is offered.

Results are estimates for general information. Double-check anything important with an official source.