Password Generator

Generate a genuinely random password or a memorable passphrase, using your browser cryptographic random source - the result never touches a network.

Runs entirely in your browser. Nothing is uploaded.

Pick at least one character set
Excellentabout 128 bits of entropy

Generated in your browser with the Web Crypto API. Nothing is transmitted, and nothing is stored.

Length beats complexity

The rules most of us learned - one capital, one number, one symbol - optimise for the wrong thing. They make passwords hard for humans to remember while adding very little difficulty for a machine, because people satisfy them predictably: the capital goes first, the number and exclamation mark go last.

Length is what actually costs an attacker time, because each additional character multiplies the search space. A sixteen-character password drawn from a decent alphabet is far stronger than an eight-character one contorted to satisfy four rules, and current guidance from NIST reflects exactly this shift.

When a passphrase is the better answer

A passphrase is several random words joined together. Four or five randomly chosen words give you strength comparable to a long random string, while remaining something a human can hold in their head and type on a phone keyboard without swearing.

The word randomly is doing the work. Words you chose yourself are not random - they cluster around your interests and are dramatically weaker than they appear. A passphrase is only strong when a machine picked the words.

Use a passphrase where you must type it from memory: a device login, a disk encryption key, a password manager master password. Use a long random string everywhere the manager types for you.

Why generating in the browser matters

A password generated on a server is a password that existed, however briefly, on someone else machine and possibly in a log. This one is generated by the Web Crypto API in your own browser, from a source designed to be unpredictable. Nothing is transmitted and nothing is stored.

The remaining advice is unglamorous and more important than the generator: use a different password on every site, keep them in a password manager, and turn on two-factor authentication wherever it is offered. A unique password limits one breach to one account.

Frequently asked questions

Are these passwords sent over the internet?
No. Generation happens in your browser using the Web Crypto API. Nothing is transmitted, logged or stored anywhere.
How long should a password be?
Sixteen characters or more for anything a password manager will type for you. Length contributes far more strength than character-class rules do.
Is a passphrase safer than a random password?
A passphrase of four or five randomly chosen words is comparably strong and far easier to type from memory. The words must be machine-chosen; self-selected words are much weaker than they look.
Do I still need special characters?
Only where a site demands them. A longer password without symbols generally beats a short one with them, though many sites still enforce the old rules.
Can the same password be generated twice?
It is theoretically possible and practically irrelevant at any reasonable length - the search space is far too large for a repeat to occur.