Password Generator
Create strong random passwords or easy-to-type passphrases using cryptographic randomness. See exactly how strong each one is before you use it.
Settings
Words are drawn uniformly from the EFF large wordlist (7,776 words ≈ 12.9 bits each).
Your password
Click regenerate as often as you like — nothing is saved.
Need several?
Generate a batch with the same settings.
How to create a strong password
Choose password or passphrase
Random passwords pack the most strength into the fewest characters. Passphrases are longer but far easier to type and remember — great for a master password.
Adjust length and characters
Longer is stronger. 16+ characters with all four character types, or 5+ random words, comfortably exceeds 64 bits of entropy.
Copy it into your password manager
Use a unique password for every account and let a password manager remember them. Reuse is the most common way accounts get taken over.
How password strength is measured
Strength is measured in bits of entropy: the base-2 logarithm of how many equally likely passwords the generator could have produced. Each extra bit doubles an attacker’s work. A 20-character password from all 94 printable ASCII characters has about 131 bits — far beyond any brute-force attack.
| Entropy | Rating | Example |
|---|---|---|
| < 40 bits | Very weak | 8 lowercase letters |
| 40–59 bits | Weak | 10 letters and digits |
| 60–79 bits | Reasonable | 12 mixed characters, or 5 random words |
| 80–99 bits | Strong | 14+ mixed characters, or 7 random words |
| 100+ bits | Very strong | 16+ mixed characters, or 8+ random words |
The crack-time estimate assumes an offline attacker trying 100 billion guesses per second against a fast hash — a pessimistic, worst-case scenario. Sites that store passwords with bcrypt or Argon2 slow attackers down by many orders of magnitude.
Why this generator is safe to use
Characters and words are chosen with crypto.getRandomValues() using rejection sampling, so every option is exactly equally likely. Generation happens entirely in your browser; nothing is transmitted, logged or stored.
Frequently asked questions
Is this password generator safe?
Yes. Passwords are generated locally with the Web Crypto API and never leave your device. The page makes no network request with your password, and nothing is saved.
How long should my password be?
Use at least 16 random characters for important accounts, or a passphrase of 5–6 random words. NIST guidance favours length over forced complexity rules.
Are passphrases as secure as random passwords?
They can be. Each word from a 7,776-word list adds about 12.9 bits, so six random words (≈77 bits) are about as strong as a 12-character random password — and much easier to type on a phone.
Why avoid look-alike characters?
Characters like l, 1, I, O and 0 are easy to confuse when reading a password aloud or typing it from another screen. Excluding them costs a little entropy, which you can recover by adding a character or two.
Where do the passphrase words come from?
From the Electronic Frontier Foundation’s large diceware wordlist, designed to contain memorable, distinct and easy-to-type English words. It is used under the Creative Commons Attribution 3.0 license.