UtilitiesProcessed in your browser, never uploaded

Secure Password Generator

Generate strong, random passwords with a strength meter and character filters

Password Strength:Very Strong
Password Length16 Characters
616 (Recommended)3264

About this tool

This Password Generator creates random passwords using your browser's built-in Web Crypto API (window.crypto.getRandomValues), rather than a weaker pseudo-random function, which makes the output suitable for real account security rather than just a quick placeholder. You can set the length anywhere from 6 to 64 characters and toggle which character sets to include — uppercase letters, lowercase letters, numbers, and special symbols — as well as optionally exclude visually ambiguous characters like 0, O, l, 1, and I, which can be easy to mistype when reading a password off a screen. A live strength indicator estimates the password's entropy in bits, giving you a rough sense of how resistant it is to brute-force guessing. Generation happens entirely in your browser; nothing you generate is transmitted or logged anywhere.

How to use

  1. 1

    Set the Length

    Use the slider to pick a password length (16+ is a reasonable default).

  2. 2

    Choose Character Sets

    Toggle uppercase, lowercase, numbers, and symbols as needed.

  3. 3

    Copy the Password

    Click Copy and paste it into your account's password field.

Features

  • Uses the browser's Web Crypto API for randomness (window.crypto.getRandomValues)
  • Adjustable length from 6 to 64 characters
  • Toggle uppercase, lowercase, numbers, and special symbols independently
  • Option to exclude ambiguous characters (0, O, l, 1, I)
  • Live entropy-based strength indicator
  • One-click copy to clipboard

Tips & common mistakes

  • •Longer passwords generally beat more complex short ones — a 20-character password with just upper/lowercase and numbers is often stronger than a 10-character one packed with symbols.
  • •If a website restricts certain special characters, try disabling the symbols toggle and regenerating rather than manually editing a generated password, since manual edits reduce randomness.
  • •Enable "exclude ambiguous characters" if you expect to ever need to type the password manually from a printed copy or over the phone.
  • •Generate a fresh password for each account rather than reusing one password with minor variations — reused passwords are a common security weakness even when individually strong.

Password Entropy Calculation

Shannon entropy is used to estimate how resistant a password is to brute-force guessing based on its length and character pool size.

Entropy (E) = L × log2(R)
  • •L = password length in characters
  • •R = size of the available character pool (e.g., 26 lowercase + 26 uppercase + 10 digits + symbols)
  • •Higher entropy values indicate a password that takes exponentially longer to brute-force

Secure Password Generator FAQ

No. Passwords are generated locally using your browser's Web Crypto API and are never transmitted to a server or logged anywhere.
Length matters most — generally 14+ characters — combined with a mix of character types and avoiding dictionary words or predictable patterns like "Password123".
Entropy measures unpredictability in bits. Higher entropy means more possible combinations an attacker would need to try, making brute-force guessing significantly harder.
Math.random() is not designed to be cryptographically secure and can theoretically be predicted in some cases, while the Web Crypto API is specifically built for generating unpredictable values suitable for security purposes.
It's optional, but useful if you'll ever need to read or type the password manually, since characters like 0/O or l/1/I can look identical in some fonts.
No. Once you navigate away or close the tab, the generated password is not stored anywhere by this tool — be sure to save it in a password manager.

Related tools

More tools from the same category and nearby utilities.