Password generator
Nothing you generate here is sent to us or to anyone else. The page does the work on your own device, so you can use it on a machine you do not fully trust and still walk away clean.
- Uses your browser's secure random generator
- Nothing is sent, saved or logged
- Passwords up to 64 characters, or memorable passphrases
Your browser does not provide a cryptographic random number generator, so this tool has switched itself off rather than fall back to something weaker. Please update your browser and try again.
Made on this device. Never sent or stored.
Common questions
Do you see or store the passwords I generate?
No. The generator runs entirely in your browser and the page has no way to send anything back to us — there is no form submission and no tracking on it. Once you close the tab the password is gone unless you saved it yourself.
How random are the passwords?
They come from your browser's built-in cryptographic random number generator, the same class of source used for encryption keys — not the ordinary Math.random(), which is predictable. If your browser cannot provide it, the tool refuses to generate rather than quietly producing something weaker.
What does "bits of entropy" mean?
It is a measure of how many guesses an attacker would need. Each extra bit doubles that number. Under 40 bits is weak, 60 to 80 is reasonable for most accounts, and 80 or more is a sensible target for email, banking and anything holding your other passwords.
Should I use a password or a passphrase?
Either, as long as the entropy is high enough. A random password is shorter and better suited to a password manager. A passphrase of five or six words is far easier to type by hand or read off a screen, which matters for your device login and your password manager's own master password.
How is the "time to crack" worked out?
It assumes the worst realistic case: someone has stolen the website's password file, it was stored with fast, outdated protection, and they are guessing offline at 100 billion attempts a second on one high-end graphics card. A site that protects passwords properly would take far longer to attack. The figure is an average, not a worst case — and a password you have reused somewhere that has already been breached is cracked immediately, however strong it looks here.
Do I still need a password manager?
Yes. The value of a strong password disappears the moment you reuse it. A manager lets every account have its own, and means you only have to remember one good passphrase. We are happy to help you set one up.
Worried about more than one password?
Reused passwords are what actually catch people out. We set businesses and households up with a password manager, and we can check whether your details have already turned up in a breach.