Password Generator
Generate cryptographically secure random passwords locally.
About Password Generator
Weak and reused passwords remain the top cause of account compromise. This generator creates random passwords using your browser's cryptographic random number generator (crypto.getRandomValues) — the same entropy source used for TLS keys — with no network transmission. Every password is generated locally and never leaves your device.
For strength, length matters more than complexity rules: a 16-character random password mixing case, digits, and symbols has about 100 bits of entropy, which is unbreakable by brute force with current technology. Use 12+ characters for general accounts and 20+ for password-manager master keys, encryption keys, and administrator accounts.
Best practice: generate one unique password per service and store them in a password manager. This tool is also handy for API keys, Wi-Fi passwords, database credentials, and one-time secrets. Note that a generator cannot protect against phishing or malware — pair strong passwords with two-factor authentication where available.
Frequently Asked Questions
Are these passwords truly random?
Yes. The generator uses the Web Crypto API's cryptographically secure random number generator, suitable for security-sensitive use. It is not the weaker Math.random().
Can the generated password be guessed or reused?
Each generation draws fresh entropy from the operating system. The chance of generating the same password twice is negligible even across billions of generations.
Which character set should I choose?
Keep all four sets enabled unless the target system rejects symbols. If a site limits length, compensate with maximum length and full character variety.