Password Generator

Very weak

Characters included:

Private by design

Made on your device

Every character comes from your browser's cryptographic random generator, the same one it uses for encryption keys. Not the predictable kind most quick generators use.

Never sent, never saved

There is no server behind the generator. What you create never leaves this page, and it is gone the moment you close it.

Strength you can check

Strength is measured, not guessed: the exact number of possibilities, and how long a well-funded attacker making 100 billion guesses a second would need.

Password or passphrase?

Both are strong. The difference is who has to remember it.

Password

k#9Rv!2mQz@4

For the logins your password manager fills in. You never type it, so it can be as random as it likes.

Passphrase

Granite-Orbit-Lantern7

For the few you type yourself: your laptop, your Wi‑Fi, your password manager. Easy to remember, still hard to crack.

Password Generator FAQs

Yes, when the generator runs entirely in your browser, as this one does. Your password is created on your device and never sent to us or anyone else. You can check: open your browser's developer tools, watch the Network tab and generate as many as you like. Nothing goes out.

Three things: it is long, it is truly random, and you use it in one place only. Length matters most, because every extra character multiplies the work an attacker has to do. Reusing a password, however strong, means one leaked site opens every account that shares it.

It can be. Each word is picked at random from 7,776, so five words give over 28 billion billion combinations, about the same as a random 10-character password. Add a sixth word and it beats most passwords people use, while staying easy to remember.

For anything a password manager fills in for you, 16 characters or more. You never type it, so longer costs you nothing. For a passphrase you type yourself, use at least five words, and six for your most important accounts, such as your email or your password manager.

We count every password your settings could produce, then assume an attacker who knows those settings and can test 100 billion guesses a second. On average they find it halfway through. Real attacks on well-protected sites are far slower, so this is a cautious estimate.

Keep them in a password manager instead. It remembers every password for you, so the only one you need to know is its own, and that is exactly what a passphrase is for. If you must write one down, keep it somewhere private and offline, never in a note on your phone or computer.

From the Electronic Frontier Foundation's long word list: 7,776 common English words chosen to be easy to spell and hard to confuse. It is the standard list for this kind of passphrase.