Live Gold PriceGold CalculatorSilver PriceSilver CalculatorliveExchange Rate
Home › Calculators › Password Generator
SECURITY

Password Generator

Strong random passwords with the Web Crypto API — nothing leaves your browser.

Your password
—

crypto.getRandomValues() picks characters uniformly from your chosen sets.

What Is a Password Generator?

A password generator creates long, random passwords that no human would invent — and that no attacker can guess. Human-chosen passwords follow predictable patterns (names, dates, "Password123!"), which is exactly what guessing attacks exploit. A generator picks each character at random from a large set, producing passwords with far more unpredictability per character than anything you'd type yourself.

How It Works

The generator uses a cryptographically secure random number source (not the predictable pseudo-random functions used in games) to select each character independently from the character sets you enable:

Password strength is measured in bits of entropy: entropy ≈ length × log₂(alphabet size). A 16-character password drawn from all 94 printable ASCII characters has about 16 × 6.55 ≈ 105 bits of entropy — meaning an attacker would need to try roughly 2¹⁰⁵ combinations on average to guess it, which is infeasible with any realistic computing power. Every extra character multiplies the search space, so length matters more than clever substitutions like "@" for "a".

How to Use This Generator

  1. Choose a length — 16 characters is a solid default; 20+ for critical accounts like email and banking.
  2. Enable the character sets you want. More sets mean more entropy per character.
  3. Click generate, copy the result, and paste it into the site's password field — don't try to memorize it.
  4. Exclude ambiguous characters (like 0/O and 1/l/I) if you'll ever need to read the password aloud.

Worked Example

Compare two example passwords (illustrative only — never reuse these):

The second password is effectively unguessable, while the first could fall to a targeted guessing attack.

Tips

Frequently asked questions

Is the password sent anywhere?

No — generation happens entirely in your browser with the Web Crypto API.

How long should a password be?

16+ characters with mixed sets resists brute force for the foreseeable future.