Password Generator

Strong passwords built in your browser and never transmitted — with the exact entropy in bits and how long each type of attacker would need to break them.

Build your password

Everything is generated in this browser tab with crypto.getRandomValues. No password is ever sent to a server, saved, or logged.

Quick presets

Advanced rules

Your password

—

— bits of entropy · —

Time to crack, by who is attacking

Generate a batch

Setting up a team, seeding test accounts, or rotating a device fleet? Generate many at once using the settings above, then export. The file is written by your browser — it never touches a server.

What the four attack speeds mean

“Time to crack” is meaningless without saying who is doing the cracking. These are the four situations your password realistically ends up in.

Online, rate-limited — 10 guesses/secSomeone is typing at your actual login form and it locks out after a handful of failures. This is the best case, and the only one you control.
Online, no rate limit — 10 thousand/secA login API with no lockout or a credential-stuffing run. Common on smaller sites and internal tools.
Offline, slow hash — 100 thousand/secThe site was breached and stored passwords properly, with bcrypt at cost 12, Argon2id or scrypt. The attacker has the hashes and a multi-GPU rig.
Offline, fast hash — 1 trillion/secThe site was breached and stored passwords badly — unsalted MD5, SHA-1 or NTLM. A GPU cluster chews through these. Assume this is what happens, because you never find out which one a site used until it is too late.

Figures assume the attacker must find your password by brute force and, on average, gets there halfway through the keyspace. If your password is a known one or a predictable variation, none of this applies — it falls in the first second regardless of length.

Related calculators

How this password generator works

Every password on this page is produced inside your own browser tab by crypto.getRandomValues, the operating system's cryptographically secure random number generator. Nothing is generated on a server, so there is no request to intercept, no log to subpoena and no database to breach. You can confirm it: open your browser's developer tools, switch to the Network tab, and generate a hundred passwords. Nothing moves.

Two details separate a careful generator from a careless one, and most free tools online get at least one of them wrong.

The first is modulo bias. The obvious way to pick a random character is to take a random 32-bit number and divide by the alphabet size, keeping the remainder. Because 232 is not evenly divisible by, say, 94, the first few characters of the alphabet come up very slightly more often than the last few. It is a small skew, but it is a real, measurable reduction in the strength you think you are getting. This page uses rejection sampling instead: any random value that falls into the uneven tail is thrown away and a fresh one drawn, so every character in the pool is exactly equally likely.

The second is the "one of each type" rule. Many generators satisfy a site's "must contain an uppercase letter and a number" requirement by forcing specific positions to specific types — an uppercase letter always first, a digit always last. That is predictable, and predictability is exactly what an attacker's rule engine exploits. This page instead generates a fully random string and rejects it if it happens to miss a required type, which keeps the result uniformly distributed across every valid password. The entropy figure shown accounts for the small amount that requirement costs, calculated exactly by inclusion–exclusion rather than guessed at.

What the entropy number actually means

Entropy, measured in bits, is the honest way to describe password strength. A password with n bits of entropy is one drawn uniformly from 2n equally likely possibilities. Add one bit and you double the work an attacker has to do. Twenty random lowercase letters is about 94 bits; a five-word passphrase from a 1,296-word list is about 51.7 bits; a four-digit PIN is 13.3 bits no matter how cleverly you choose it.

This matters because the coloured strength meters on most sites are not measuring entropy at all. They count character types and length and award a green bar. By that logic P@ssw0rd1 scores well — it has uppercase, lowercase, a digit and a symbol across nine characters — while it is in fact one of the first few thousand guesses any cracking rig tries. The number on this page is computed from the actual generation space: the size of the character pool, the length, and any rules you switched on. No tool can measure the guessability of a password a human invented without knowing how they invented it, which is why a generated password with a known character pool is the only one whose strength can be stated honestly.

Length beats complexity — and the standards now say so

NIST Special Publication 800-63B, the US federal digital identity standard, was revised in 2025 and reversed decades of received wisdom. Under Revision 4, a password used as the only factor protecting an account should be at least 15 characters; 8 is the floor when multi-factor authentication is also in place. Systems are told to accept at least 64 characters, to allow spaces and Unicode so that passphrases work, and to stop imposing composition rules — no more mandatory "one uppercase, one number, one symbol". Scheduled expiry is out too: passwords should be changed on evidence of compromise, not on a 90-day timer.

The reasoning is behavioural rather than mathematical. Complexity rules and forced rotation do not produce random passwords; they produce Summer2025! followed by Autumn2025!. Length, by contrast, cannot be faked. Revision 4 also makes screening against known-compromised passwords a requirement — a rule that matters most for passwords people invent themselves. A generated password never appears on a compromised list, because it has never existed before.

If you want to know whether a password you already use has appeared in a breach, Have I Been Pwned offers a range-query API that never sees your full password.

Random string or passphrase?

Use a random string for anything you will never type from memory — which, if you use a password manager, is almost everything. Twenty characters across all four types is comfortably beyond reach of any offline attack that exists or is plausibly coming.

Use a passphrase for the handful you must actually remember: your password manager's master password, your device login, your email account. Words from a fixed list are far easier to recall and to type on a phone or a TV remote than a symbol soup, and the entropy is exact and calculable because the words are drawn uniformly at random. Six words from the 1,296-word list is 62 bits; seven is 72; eight is 82.7. The list used here is the EFF short wordlist, chosen because every word is at most five letters, unambiguous when spoken aloud, and distinct enough from the others that autocomplete and typo-correction work in your favour.

What does not work is inventing a passphrase yourself. "correct horse battery staple" is strong because the words were chosen by dice; the same four words picked by a person thinking of things in the room are not. Human word choice clusters hard, and cracking wordlists are built from exactly that clustering.

Where the rest of the risk lives

A generated password removes one class of risk and leaves the others standing. Reuse is the big one: a 30-character password used on two sites is only as safe as the weaker site. Generate a new one per account and store them somewhere — a password manager, or genuinely, written on paper in a drawer, which beats reuse comfortably for most people's threat model. Phishing is the other: no password length defends against typing it into a convincing fake, which is why phishing-resistant multi-factor authentication (a passkey or a hardware key) is now the thing standards bodies push hardest.

And treat the clipboard as leaky. Other applications can read it, and on some systems it syncs between devices. Paste straight into your password manager and then copy something harmless over the top.

Frequently asked questions

Are these passwords actually random, or generated on your server?
They are generated entirely inside your browser tab using crypto.getRandomValues, the operating system's cryptographically secure random source. No password is transmitted, stored or logged anywhere. You can verify this by opening your browser's developer tools, switching to the Network tab and generating passwords - no requests are made. The page also strips out its own save, share-link and download-image buttons so that a generated password cannot accidentally be written to your history or a URL.
How long should my password be in 2026?
NIST SP 800-63B Revision 4, finalised in 2025, sets 15 characters as the recommendation when a password is the only thing protecting an account, and 8 characters as the minimum when multi-factor authentication is also in place. Systems are told to accept at least 64 characters. For anything you care about, 16 to 20 random characters is a sensible target, and a password manager makes the length free.
What does 'bits of entropy' mean?
A password with n bits of entropy was drawn uniformly from 2^n equally likely possibilities. Each extra bit doubles the attacker's work. Roughly: under 36 bits is very weak, 60 to 80 bits is reasonable for an account with rate limiting, and above 80 bits is beyond any offline attack that currently exists. Twenty random characters using all four character types is about 131 bits.
Is a passphrase safer than a random string?
Neither is inherently safer - it depends on the entropy. Six random words from the 1,296-word list used here is about 62 bits; sixteen random characters across all four types is about 105 bits. The random string wins mathematically. The passphrase wins when you have to remember and type it, which is why the right split is passphrases for the few you memorise (password manager master password, device login, email) and long random strings for everything else.
Why does the tool tell me to avoid capitalising the first letter of every word?
Because a rule everybody follows adds nothing. If an attacker knows the passphrase format is Word-Word-Word with each word capitalised, the capitalisation contributes zero bits - there is only one way to do it. Choosing capitalisation at random per word adds one bit per word, which is why that option is labelled as adding entropy and the others are not.
Should I still change my passwords every 90 days?
No. NIST SP 800-63B Rev 4 explicitly tells organisations to stop forcing periodic changes and to require a change only on evidence of compromise. Scheduled rotation pushes people towards predictable variations - Summer2025! becoming Autumn2025! - which is worse than leaving a strong password in place. Change a password when a service discloses a breach, when you suspect exposure, or when it is weak or reused.
What is modulo bias and why does it matter?
It is a subtle flaw in how many generators map random numbers onto an alphabet. Taking a random 32-bit value and using the remainder after dividing by the alphabet size makes the earliest characters slightly more likely, because 2^32 does not divide evenly by most alphabet sizes. The skew is small but it genuinely reduces strength below the advertised figure. This page uses rejection sampling - values falling in the uneven tail are discarded and redrawn - so every character is exactly equally likely.
Can I generate passwords for a site with awkward rules?
Yes. The advanced options let you set exactly which symbols are allowed, exclude specific characters a system rejects, cap the length, avoid look-alike characters such as I, l, 1, O and 0 for passwords that must be read aloud or typed from a printout, and forbid repeated characters or runs like abc and 123. Pattern mode handles fixed formats: A gives an uppercase letter, a a lowercase letter, 9 a digit, # a symbol, and any other character is copied straight through.
Is it safe to copy a password to the clipboard?
It is the normal way to move one, but the clipboard is readable by other applications on your machine and on some systems it syncs across devices. Paste it straight into your password manager, then copy something harmless over the top so the password is not left sitting there. Browsers do not let a page clear your clipboard once you navigate away, so this is a habit rather than something a website can do for you.
How many passwords can I generate at once?
Up to 500 in a single batch using whatever settings you have chosen, with copy, .txt and .csv export. The file is assembled by your browser and saved directly to your device - it is never uploaded. This is intended for onboarding a team, seeding test accounts or rotating a fleet of devices.
Is this password generator free?
Yes, completely free, with no account, no sign-up and no limit on how many passwords you generate.

How ListCalc calculates · Report an error

Guides & articles