16 characters, every kind
16 × log2(90) ≈ 103 bits — very strong.
Create strong random passwords with the length and characters you choose, generated privately in your browser.
Choose your options and select Generate.
Runs in your browser — nothing you enter is sent to a server.
Choose a length and the kinds of characters to use, then select Generate password. Each character is picked with your browser's cryptographically secure random generator (crypto.getRandomValues) using unbiased sampling, so every allowed character is equally likely. The password always contains at least one character of each kind you chose.
Passwords are created on your device and never sent, stored or logged. Close the page and they're gone — save the one you use in a password manager.
bits = length × log2(pool)
Where:
Each extra bit doubles the number of guesses an attacker needs. The tool rates under 50 bits as weak, 50–69 fair, 70–99 strong and 100 or more very strong.
16 × log2(90) ≈ 103 bits — very strong.
8 × log2(10) ≈ 26 bits — weak: fine for a one-time code, not for an account password.
At least 16 characters for accounts you care about, when the site allows it. Length adds more strength than symbols: 20 lowercase letters (94 bits) beat 12 characters of every kind (77 bits).
If you'll ever read a password aloud or type it from paper, characters like I, l, 1, O and 0 cause mistakes. Leaving them out costs a little strength, which the entropy figure shows.
Yes — they come from the same secure random source browsers use for encryption keys, and never leave your device. Use a different password for every site.
Generate random strings from letters, digits, hex, URL-safe characters or your own set, in bulk.
Generators
Generate random version 4 or time-ordered version 7 UUIDs, up to 1,000 at a time.
Developer Tools
Generate truly random numbers in any range — one or many, whole or decimal, with or without repeats.
Generators