A everyday account password
Twenty characters with all four types is comfortably past a hundred bits, which is beyond brute force for any realistic attacker. Store it in a manager and never see it again.
Generate strong passwords in your browser using crypto.getRandomValues, with entropy shown in bits.
Maintained by Roshan.
Passwords are drawn from crypto.getRandomValues, your browser's cryptographic random source, and never sent anywhere.
Find related browser-local tools for nearby tasks without starting another search.
Browse all generatorsThe only thing that matters in a password generator is where the randomness comes from, and it is the one thing you cannot see by looking at the output. A password produced by a weak source looks exactly as scrambled as one produced by a strong source, right up until someone reproduces it. This generator draws from your browser's cryptographic random source, discards draws that would skew the result, and shows the strength in bits so the number is not a marketing adjective. It runs on your device, so the password exists nowhere else at the moment it is created.
Twenty characters with all four types is comfortably past a hundred bits, which is beyond brute force for any realistic attacker. Store it in a manager and never see it again.
Turn on the lookalike filter and drop symbols. Strength falls, so raise the length to compensate; the result is longer but survives being read over a phone.
Some banks still cap passwords at twelve characters. Use every character type allowed, accept the lower entropy, and make sure that password is unique to that one site.
No. It is generated in your browser and exists only in this tab. The site has no endpoint that could receive it, no analytics runs on the page, and nothing is written to storage. Closing the tab is the end of it.
It is designed for speed, not secrecy. Its internal state can be reconstructed from output it has already produced, which means passwords built from it can be predicted. Cryptographic generators are specifically built to make that infeasible.
Below 40 is weak, 60 is fair, 80 is strong, and above 100 is beyond any realistic brute-force attempt. The figure shown updates as you change the length and character types.
They help, but less than people assume. Going from letters and digits to adding symbols gains a few bits per character; adding several more characters gains more. Include them unless the destination rejects them.
Random mode deliberately creates a new password every time. Reproducible mode can recreate a password from the same master phrase and saved non-secret recipe, but it cannot recover a forgotten phrase or infer missing settings.
No. The phrase is used by Web Crypto inside this tab and is not included in the copied recipe. It is never uploaded or written to browser storage.
Generate one or a thousand version 4 UUIDs in your browser using a cryptographic random source. Copy them all at once, with nothing requested from a server.
Produce SHA-1, SHA-256, SHA-384, or SHA-512 digests from text in your browser using Web Crypto. Nothing is uploaded, so pasting sensitive text is safe.
Encode UTF-8 text to standard Base64 or decode Base64 back to Unicode text locally in your browser, with strict malformed and non-text error handling.
Make a QR code from a link or any text in your browser. No redirects, no expiry, no account, and nothing sent to a server.
Turn a .env file into JSON in your browser. Handles export prefixes, quotes and inline comments.