Shard Tools

Password Generator

Generate strong passwords in your browser using crypto.getRandomValues, with entropy shown in bits.

Maintained by Roshan.

Use Password Generator

Passwords are drawn from crypto.getRandomValues, your browser's cryptographic random source, and never sent anywhere.

Never generated from Math.randomMath.random is fast but predictable: given enough output, future values can be inferred. This tool uses the cryptographic generator instead, and discards biased draws so every character is equally likely.

Explore generators

Find related browser-local tools for nearby tasks without starting another search.

Browse all generators

About Password Generator

The only thing that matters in a password generator is where the randomness comes from, and it is the one thing you cannot see by looking at the output. A password produced by a weak source looks exactly as scrambled as one produced by a strong source, right up until someone reproduces it. This generator draws from your browser's cryptographic random source, discards draws that would skew the result, and shows the strength in bits so the number is not a marketing adjective. It runs on your device, so the password exists nowhere else at the moment it is created.

Build the document

  1. Every character comes from crypto.getRandomValues, the interface browsers expose for cryptographic randomness. It is explicitly not Math.random, which is a fast general-purpose generator whose future output can be worked out from values it has already produced. For a password that difference is the whole game.
  2. Biased draws are thrown away rather than folded in. Mapping a random byte onto an alphabet by remainder makes the first few characters slightly more likely whenever the alphabet does not divide 256 evenly, so any byte landing in the biased tail is discarded and a new one drawn. Every character is then equally likely.
  3. Pick the length and which character types to include. Strength in bits is recalculated as you change either, because both matter: bits are the length multiplied by the log of the alphabet size.
  4. Turn on the lookalike filter when a password has to be read aloud, copied from a screen, or typed on a television remote. It removes characters like l, I, 1, O and 0 that people routinely confuse, at a small cost in strength.

Ways to use Password Generator

A everyday account password

Twenty characters with all four types is comfortably past a hundred bits, which is beyond brute force for any realistic attacker. Store it in a manager and never see it again.

A password you have to dictate

Turn on the lookalike filter and drop symbols. Strength falls, so raise the length to compensate; the result is longer but survives being read over a phone.

A field with a short maximum

Some banks still cap passwords at twelve characters. Use every character type allowed, accept the lower entropy, and make sure that password is unique to that one site.

Check before sending it

Questions about Password Generator

Is the password sent anywhere or stored?

No. It is generated in your browser and exists only in this tab. The site has no endpoint that could receive it, no analytics runs on the page, and nothing is written to storage. Closing the tab is the end of it.

Why does Math.random matter so much?

It is designed for speed, not secrecy. Its internal state can be reconstructed from output it has already produced, which means passwords built from it can be predicted. Cryptographic generators are specifically built to make that infeasible.

How many bits are enough?

Below 40 is weak, 60 is fair, 80 is strong, and above 100 is beyond any realistic brute-force attempt. The figure shown updates as you change the length and character types.

Should I include symbols?

They help, but less than people assume. Going from letters and digits to adding symbols gains a few bits per character; adding several more characters gains more. Include them unless the destination rejects them.

Can I generate the same password again later?

Random mode deliberately creates a new password every time. Reproducible mode can recreate a password from the same master phrase and saved non-secret recipe, but it cannot recover a forgotten phrase or infer missing settings.

Is the master phrase saved or uploaded?

No. The phrase is used by Web Crypto inside this tab and is not included in the copied recipe. It is never uploaded or written to browser storage.

Related tools

UUID Generator

Generate one or a thousand version 4 UUIDs in your browser using a cryptographic random source. Copy them all at once, with nothing requested from a server.

Hash Generator

Produce SHA-1, SHA-256, SHA-384, or SHA-512 digests from text in your browser using Web Crypto. Nothing is uploaded, so pasting sensitive text is safe.

Base64 Encoder and Decoder

Encode UTF-8 text to standard Base64 or decode Base64 back to Unicode text locally in your browser, with strict malformed and non-text error handling.

QR Code Generator

Make a QR code from a link or any text in your browser. No redirects, no expiry, no account, and nothing sent to a server.

ENV to JSON

Turn a .env file into JSON in your browser. Handles export prefixes, quotes and inline comments.