Password Generator

Strong random passwords or memorable passphrases. Generated locally — never sent anywhere.

Enter input above to see the result.

Entropy: the only number that matters

A good password is one an attacker can't guess and you don't have to remember (because it's stored in your password manager). This generator produces strong random passwords or memorable passphrases entirely in your browser, using crypto.getRandomValues — the same cryptographically secure random source TLS uses. Nothing is transmitted; the password never leaves your device.

Characters vs words — picking a mode

Strength thresholds at a glance

Where passwords go wrong after generation

Why length is the only knob that scales

20-character password vs 4-word passphrase

In characters mode, set length 20 with lowercase, uppercase, digits and symbols enabled and you get something like k7$Rp2!mQ9xZ&4nB8vLt — drawn from a ~90-character pool, that's about 130 bits of entropy, rated "very strong". Switch to passphrase mode and it strings together random words (anchor-buffet-cavern-mellow) that are far easier to type and remember while still being strong. You can generate several at once and copy them.

Entropy, randomness, and the ambiguous-character toggle

Is the randomness actually secure? Yes — it uses the browser's cryptographic RNG (crypto.getRandomValues), not Math.random. That's the difference between passwords an attacker can't predict and ones that are theoretically reproducible.

How is the entropy figure calculated? For character passwords it's length × log₂(pool size); for passphrases it's words × log₂(list size) — the honest information-theoretic strength, assuming the attacker knows your settings. The strength label steps up at roughly 60, 80 and 100 bits.

What does "exclude ambiguous" do? It removes easily confused glyphs (0 O 1 l I) from the pool, so a password is safe to read aloud or copy by hand. It slightly shrinks the pool, which the entropy estimate accounts for conceptually.

Are passphrases weaker than random strings? Not necessarily — a four-word phrase from a large list rivals a 12-character random password for guessing resistance while being much easier to type. Add a word for more strength. Every password is generated in your browser and never transmitted or logged.