Lang
Private, cryptographically secure password tool
Password Generator
Create strong random passwords, memorable passphrases or PINs entirely in your browser. Nothing generated by this tool is sent, saved or added to your history.
Generated locally in your browserBuild a secure password
Choose a preset or customise every setting. New values are created with the browser’s cryptographically secure random generator.
Quick presets
Created on this device
Your generated results
Copy the value directly into a trusted password manager. Do not reuse it for another account.
Entropy is a mathematical estimate for values produced by this generator, not a promise of how long a real attack would take. Phishing, malware and password reuse bypass brute-force strength.
Private by design
Generation happens in JavaScript on this device. The tool does not transmit, log, store, analyse or place generated secrets in the page URL. Reloading the page removes them.
Only copy passwords on a trusted device. Browser extensions, malware or screen recording software may still be able to see what is displayed.
What makes this generator safer
Cryptographic randomness
The generator uses Web Crypto rather than Math.random(), and rejects biased random values before selecting characters or words.
Guaranteed character groups
When enabled, every selected character group appears at least once and the completed password is securely shuffled.
No secret history
Generated values are never written to localStorage, cookies, analytics events or shareable URLs by this tool.
Conservative guidance
The strength display focuses on length and estimated search space and does not claim a guaranteed crack time.
Practical password security checklist
- Use a unique password for every account so one breach cannot unlock another service.
- Save generated passwords in a reputable password manager rather than trying to memorise them.
- Protect the password manager with a long master passphrase and multi-factor authentication.
- Choose passkeys or phishing-resistant multi-factor authentication when a service offers them.
- Never send a password by email, chat or a shared document.
- Change a password when compromise is suspected; routine forced changes are not a substitute for unique strong passwords.
Security guidance and methodology
Current NIST guidance emphasises password length, unique passwords, password-manager support and permitting long passphrases. The Web Crypto API supplies cryptographically strong random values in modern browsers.
Secure Password Generator FAQ
Are passwords generated on the server?
No. This tool generates every password, passphrase and PIN locally in your browser. The generated value is not included in a request to the website.
Does the website save my generated password?
No. This tool does not write generated secrets to storage, cookies, analytics events or URLs. The visible result disappears when the page is reloaded.
Why is Web Crypto better than Math.random()?
Web Crypto is designed to provide cryptographically strong random values. Math.random() is useful for simulations and interface effects but is not suitable for generating secrets.
How long should a generated password be?
Twenty random characters is a strong practical default for many accounts. Use the longest unique password the service accepts and store it in a password manager.
Is a passphrase as secure as a random password?
It depends on how many words are chosen and the size of the source list. Randomly selected words can be strong, but short human-created phrases and famous quotations are predictable.
Should every password contain symbols?
For a randomly generated password, adding symbols increases the available character pool. Length and uniqueness are more important than predictable substitutions in a password chosen by a person.
What does entropy in bits mean?
It represents the approximate number of equally likely possibilities produced by the selected generator settings. Each additional bit doubles the theoretical search space.
Can I generate several passwords at once?
Yes. Choose one, five or ten results. Each value is generated independently with secure browser randomness.
Should I check a generated password against breach databases?
A sufficiently long value from a secure random generator is extremely unlikely to match a reused password. Sending a new secret to another service would create unnecessary exposure.
Is a PIN a replacement for a password?
Usually not. Numeric PINs have a much smaller search space and should be used only in systems that require them and enforce attempt limits or device protection.
Should I regularly change every password?
Change passwords after suspected compromise, accidental disclosure or a service breach. Unnecessary scheduled changes can encourage predictable variations and do not replace uniqueness.
What else protects an account?
Use multi-factor authentication or passkeys, keep devices updated, verify website addresses and watch for phishing. A strong password cannot protect against every attack.
