Assumes 10 billion guesses per second against a properly hashed password

    Generated passwords live only on this screen. Reload and they are gone

    Type a password to see its strength

    Checked locally in your browser โ€” nothing is stored or sent. Still, avoid typing a real password on a shared computer

    "At least 8 characters with upper, lower, a number and a symbol" โ€” stop inventing them, pick one here

    How to use it

    1. Choose a tab: Random, Passphrase or PIN. Random opens first.
    2. On the Random tab, drag the length slider (8โ€“64) and tick the character types you need. Five fresh passwords appear every time you change something. Turn on Skip look-alikes if you will read the password out loud or type it from paper.
    3. Tap a line, or its copy button, to put it on the clipboard. The bar next to each one is its strength; the text below is how long a brute-force attack would take.
    4. Passphrase joins four to six random English words. It is long, which is what matters, yet easy to remember and to type on a phone.
    5. PIN gives you 4- or 6-digit codes for door locks, cards and app locks.
    6. The Check a password box at the bottom rates any password you type: length, character types, entropy and estimated crack time. Nothing you type there leaves your browser.

    Everything runs locally with crypto.getRandomValues. No password is logged, and refreshing the page discards them, so copy what you want to keep.

    Length beats complexity

    A password's strength comes far more from how long it is than from how many character types it mixes. Sixteen lowercase letters (about 75 bits) beat eight characters drawn from every type (about 52 bits) by a wide margin. Adding four more letters helps more than forcing in a symbol.

    The standards agree. NIST's digital identity guidelines (SP 800-63B) ask for a minimum of eight characters, encourage long passphrases, and specifically advise against forced composition rules and scheduled password changes. This generator's default of 16 characters clears that bar comfortably.

    AvoidBirthdays, phone numbers, names, keyboard walks (qwerty, 1q2w3e4r), repeats (aaaa1111), one dictionary word plus a digit (apple1)
    Fine12+ random characters, four or more unrelated words, a sentence only you would type
    Most importantA different password for every site. One breach otherwise opens every account that shares it

    Estimated crack times

    The table assumes ten billion guesses per second, roughly what a few GPUs manage against a fast hash. Sites that use a slow hash (bcrypt, Argon2) push these numbers up by thousands; sites that store passwords in plain text make them meaningless.

    8 chars, digits only0.01 s
    8 chars, lowercaseabout 21 s
    8 chars, all four typesabout 7 days
    12 chars, lowercaseabout 3.7 years
    12 chars, all four typesabout 150,000 years
    16 chars, all four typesabout a trillion years
    5-word passphrase from a 300-word listunder a second if the list is public โ€” add words or a number

    The on-screen rating is the entropy in bits, log2 of (alphabet size to the power of length): under 40 is weak, under 60 fair, under 80 strong, above that very strong. Passphrases are rated by the number of possible word picks, which is deliberately conservative.

    Matching a site's rules

    Symbol requiredTick Symbols. Every generated password contains at least one of each ticked type.
    Symbols not allowedUntick Symbols and add about four characters of length; 12 alphanumerics beat 8 with symbols.
    Maximum lengthSet the slider to the limit. Banks and government sites often cap at 16 or 20.
    Must start with a letterTurn on Don't start with a symbol.
    No spacesKeep the passphrase separator as a hyphen, underscore or dot.

    Keeping passwords safe

    • One per site. Use your browser's or OS's password manager, or a dedicated one, and feed it 32+ character random passwords.
    • Turn on two-factor authentication for email, banking and social accounts. A leaked password alone then is not enough.
    • Check for breaches. Look your email up on a breach-notification service and change any password that shows up.
    • Scheduled changes are not required. Change a password when there is a reason to, not on a calendar; bumping the trailing digit each month makes it weaker.

    FAQ

    Does this site store the passwords it makes?

    No. Generation and checking happen in your browser's JavaScript; there is no code that sends them anywhere, and they never appear in the URL.

    Is a passphrase safer than a random password?

    At equal length, random wins. But a passphrase can be much longer and still memorable, so a 20-character phrase usually beats a 12-character random string. Use random for anything stored in a manager, a passphrase for what you type by hand.

    How many digits should a PIN have?

    Six if allowed. A four-digit PIN has only ten thousand combinations. Avoid years, birthdays and repeated digits.

    Related tools

    • QR Code Generator โ€” share a Wi-Fi password as a QR code instead of spelling it out.
    • What Is My IP โ€” compare a suspicious login alert with your own address.
    • Character Counter โ€” check a password against a site's length limit.