Password generator

Generate random passwords, easy-to-remember passphrases, or PINs with a cryptographically secure random generator. Everything happens on your device.

—
—

16

From 4 to 128

More options

You can edit the list.

Added to the sets you picked.

From 1 to 50

  • Use a password manager so you do not have to remember them.
  • Turn on two-step verification on important accounts.
  • Do not reuse the same password on different sites.

Step by step

How to use it

  1. Pick the type: random password, passphrase made of words, or numeric PIN.
  2. Set the length and the characters you want to use. The password regenerates on its own with every change.
  3. Check the strength: we show the bits of entropy and the estimated time it would take to guess it.
  4. Copy the password with one click. If you generated several, you can copy them all or download them.
  5. Save it in a password manager: it is not kept here.
FAQ

Frequently asked questions

Are the passwords I generate sent or stored anywhere?

No. They are generated on your device with the browser’s cryptographic random number generator and never leave it. They are not saved either: we only remember your settings, such as the length and the types of characters.

How long should a strong password be?

For important accounts, use 16 characters or more with letters, numbers, and symbols. A passphrase of 5 or 6 random words is also very strong and easier to remember. The longer it is, the harder it is to guess.

What do bits of entropy mean?

They measure how many combinations are possible. Each extra bit doubles an attacker’s work. Below 40 bits is weak, 60 to 80 is strong, and 80 or more is very strong. It is an estimate for randomly generated passwords.

What is a passphrase?

It is a password made of several randomly chosen words, such as “carbon-eclipse-tulip-gravel-hammock”. Each word comes from the EFF Large Wordlist, filtered to 7,773 words, so each word adds about 12.9 bits. Six words add up to about 77 bits and are much easier to remember than a string of symbols.

What if a website rejects some of the symbols?

Some sites only accept certain symbols or limit the length. Edit the “Allowed symbols” list in More options, or turn off “Symbols” and use a longer password instead. Length adds more strength than rare symbols.

Does the strength checker send my password anywhere?

No. The analysis looks for weak patterns such as sequences, keyboard rows, years, and common words and passwords directly in your browser. Even so, avoid typing the real passwords of important accounts into any site you cannot audit.

How to create a password that cannot be guessed

What matters is length and randomness. A short password with “weird” symbols is usually easier to guess than a long one made of random words. Avoid dates, names, sports teams, and sequences like “qwerty” or “123456”.

Tips for using them well

  • Use a different password for every account; if one leaks, the others stay safe.
  • Store them in a password manager and protect it with a long passphrase.
  • Turn on two-step verification, especially for email and money accounts.
  • Change a password if you suspect it leaked, not out of routine.

When to use each mode

A random password is ideal when a password manager will store it. A passphrase suits what you do have to remember, such as the master password of your manager or the login of your computer. A PIN is only for systems that lock you out after a few attempts, like a phone or a bank card.

Updated on September 29, 2026