Make a password nobody can guess.
Generate a strong random password or a passphrase mixed with your own words, and see exactly how strong it is. Everything happens in your browser, and nothing is sent or stored.
Free, no account, unlimited. Made in your browser with its secure random generator. Nothing is sent anywhere or stored.
- Random passwords, 8 to 64 characters
- Passphrases using your own words
- Entropy in bits and time to guess
- Made in your browser, never sent
- Free, no account, unlimited
What you get
A strong password, and the numbers to prove it.
Each password comes with its length, its entropy, a strength rating and how long a fast attacker would need to guess it, plus five more to pick from.
password generator · random
done
- passwordvR7#qK2m!Xp9zT4w
- length16 characters
- entropy102 bits
- strengthVery strong
- time to guessOver a trillion years
- passphraseMaple-Chuck-Widow-Clay7-Lure-Bush-Thump-Ivory
5 more alternativesmade in your browser
Why it matters
Most stolen accounts start with a weak password.
Attackers rarely guess one password at a time. They take lists leaked from other sites and test billions of likely passwords a second against them.
Reuse
One leak opens every account
A password used on two sites is only as safe as the weaker site. A fresh random password for each account keeps a breach in one place.
Guessing
Human choices are predictable
Names, dates, keyboard runs and a capital with a 1 at the end are the first things cracking tools try. Randomness is what they cannot shortcut.
Proof
Strength you can measure
Entropy counts how many passwords the method could have made. Every extra bit doubles the work for an attacker, so you can see when a password is enough.
Who it's for
For anyone with an account worth keeping.
01
Anyone signing up
Make a unique password for each new account and save it straight into your password manager.
02
Site owners
Lock down the logins that run your website: the CMS admin, hosting, domain registrar and DNS.
03
Agencies and freelancers
Set strong passwords for client accounts you create, instead of reusing a pattern across clients.
04
Developers
Generate database passwords, test account logins and other secrets without leaving the browser.
How it works
Random by design, private by default.
01
Choose a password or a passphrase
Set a length and the characters to use, or pick how many random words to mix with words of your own.
02
Your browser draws the randomness
Every character and word comes from your browser's secure random generator, with every choice equally likely. Nothing leaves the page.
03
Copy it and store it safely
Copy the password or one of five alternatives, and keep it in a password manager rather than a note or a spreadsheet.
FAQ
Questions, answered.
Yes. Passwords are made in your browser with its secure random generator (crypto.getRandomValues), the same source password managers use. Nothing you generate or type is sent to us or stored anywhere, and once the page has loaded it works without an internet connection.
Length and true randomness. A password picked by a person follows patterns that cracking tools try first, however clever it looks. A random password of 16 characters using capitals, small letters, digits and symbols has about 102 bits of entropy, far beyond what anyone can guess.
Yes. Open the Passphrase tab and type a few words of your own. The generator mixes them in at random places among random words, so the result is easier to remember. Be aware that your own words add little strength, because people who know you, or a list of common words, can guess them. The strength shown counts only the random parts.
A passphrase generator strings together randomly chosen words, such as Chuck-Widow-Clay7-Lure. This one draws from the EFF short wordlist of 1,296 words, so each word adds about 10.3 bits. Seven words with a digit come to about 79 bits, which is strong and still easy to type.
From the way the password was made, not from how it looks. Entropy is the number of bits needed to count every password the chosen settings could produce, all equally likely. Under 50 bits is weak, under 70 is fair, under 100 is strong and 100 or more is very strong.
It is how long an attacker who knows exactly how your password was made would need at ten billion guesses a second, finding it halfway through on average. That pace is possible against a leaked database of quickly hashed passwords. Logging in through a website is far slower, so the real figure is usually much longer.
Both are strong when they have enough entropy. A random password packs more strength into fewer characters, which suits anything kept in a password manager. A passphrase is easier to remember and type, which suits the few passwords you enter by hand, such as the one that unlocks your password manager.
Yes. If a draw misses one of the types you ticked, the whole password is drawn again. That keeps every qualifying password equally likely, and the entropy shown accounts for the rule.
Capital I, small l, the digit 1, capital O and the digit 0 are easy to confuse in many fonts, which matters when you read a password out or type it from paper. Leaving them out lowers the entropy very slightly, and the figure shown reflects that.
Yes. Reused passwords are how one breach turns into many, because attackers try leaked logins on other sites. Generate a new password for each account, keep them in a password manager, and turn on two-factor sign-in where a site offers it.
Free SEO tools