Skip to content
Case Converter Online
en

Strong Password Generator

Make a long, random password in one click and see how strong it is in bits. Passwords are created on your device and are never sent or saved.

Characters to use
Options

Passwords are made on your device with crypto.getRandomValues. They are never sent, logged or saved. Keep them in a password manager.

What makes a password strong

A strong password is one that an attacker cannot guess in any practical amount of time. Two things decide that: how long it is, and how many different characters each position could be. Randomness matters too. A password you invent, such as a pet’s name with a year on the end, is far easier to guess than its length suggests, because people choose in predictable ways.

This tool picks every character at random from the sets you allow. That makes its strength easy to measure, and it means there is no pattern to exploit.

How to use the password generator

  1. A new password appears in Your password as soon as the page loads.
  2. Drag the Length slider, or use the minus and plus buttons, to choose from 4 to 128 characters. The default is 20.
  3. Under Characters to use, turn Uppercase, Lowercase, Numbers and Symbols on or off.
  4. Choose your options:
    • Avoid look-alikes (I l 1 O 0) removes characters that are easy to confuse.
    • Use every chosen type makes sure at least one character from each selected set appears.
  5. Press New for another password, and Copy to copy it.
  6. Need several? Pick a number in How many passwords. They appear in All passwords, and Copy all copies the whole list.

Below the password, a bar and a label show the strength with an estimate in bits.

Strength labels

Bits of entropy Label
under 28 Very weak
28 to 44 Weak
45 to 63 Fair
64 to 99 Strong
100 or more Very strong

Examples

These passwords and figures come from running the generator. Do not use them, since they are now public.

Length Characters Bits Label Example
6 Numbers 19.93 Very weak 546382
8 Lowercase 37.60 Weak orvapcvl
8 All four sets 51.93 Fair QpF4b@<V
12 All four sets 77.90 Strong .y9}g-.ta$rP
16 Letters and numbers 95.27 Strong ydrGkOZ9PrXPB6TL
16 All four sets 103.87 Very strong Aj~oJ-WDTW}8rJu2
20 All four sets 129.84 Very strong CwEfwEyMg)>w~b-tMx.9
20 All four, no look-alikes 127.50 Very strong B;8#]&Dr/*3X8y]fP#-P

Notice that length does more than variety. Going from 8 to 16 characters with all four sets roughly doubles the bits.

How it works

The four sets hold 26 capitals, 26 small letters, 10 digits and 28 symbols, for 90 characters in total. Avoid look-alikes removes 7 of them: I, l, 1, the pipe, O, 0 and o. That leaves 83.

Each character is drawn with crypto.getRandomValues, the browser’s cryptographic random number source. The tool maps random numbers to characters with rejection sampling instead of a plain remainder, so every character in the pool is exactly as likely as any other.

When Use every chosen type is on, a password that happens to miss one of your chosen sets is thrown away and a new one is drawn. That keeps the result evenly random.

The strength estimate is the length multiplied by log2 of the pool size. For 20 characters from 90, that is 20 x 6.49, about 129.84 bits. This is an upper bound. Requiring every type slightly reduces the number of possible passwords, by a small amount for normal lengths.

Privacy and security

  • Nothing leaves your device. There is no server step. The password exists only on the page until you copy it.
  • Nothing is saved. Reload the page and the passwords are gone. There is no history on this tool, on purpose.
  • Clear your clipboard after pasting on a shared computer.
  • Use a password manager. A random password is only useful if you can store it safely. Managers can fill it in for you, so length costs you nothing.
  • Turn on two-factor sign-in where you can. A strong password does not help if it is stolen by a fake login page.

The bits shown assume the password was generated randomly, as here. They do not apply to a password you made up and typed into another checker.

Other ways to generate a password

On a computer with Python, this prints a new 20-character password of letters and digits each time:

python -c "import secrets, string; a = string.ascii_letters + string.digits; print(''.join(secrets.choice(a) for _ in range(20)))"

With OpenSSL installed, openssl rand -base64 18 prints 24 random characters. Most password managers also have a built-in generator.

Avoid the RAND function in Excel and Math.random in JavaScript for passwords. They are not designed to be unpredictable.

For unique IDs rather than secrets, use the UUID generator. For random numbers in a range, use the random number generator. To make a checksum of a file, use the MD5 hash generator.

Password Generator: questions and answers

How long should a strong password be?

For most accounts, 16 characters or more using upper and lower case letters, numbers and symbols. That gives about 104 bits of entropy with this tool, which is far beyond what guessing attacks can reach. If you must type the password by hand often, a longer password with only letters and numbers is also fine: 24 such characters give about 143 bits.

Is it safe to use an online password generator?

It depends on how it works. This one runs entirely in your browser using crypto.getRandomValues, the random source built into your browser for security work. The password is never sent to a server, logged or stored. You can even load the page, go offline and keep generating.

What does bits of entropy mean?

It measures how many guesses an attacker would need. Each extra bit doubles the number of possible passwords. The tool works it out as the length times log2 of the number of characters it can choose from. A 20-character password from all four sets has about 129 bits.

Why avoid look-alike characters?

Characters like capital I, small l and the digit 1, or capital O and zero, are easy to mix up when you read a password off a screen or paper. Turning on Avoid look-alikes removes them. The password gets slightly weaker per character, so add a character or two to make up for it.

Should I reuse a strong password on several sites?

No. If one site leaks it, attackers will try it everywhere else. Use a different password for every account and keep them in a password manager.