Strong Password Generator
Pick a length and the character types you want and get up to 20 passwords at once. Randomness comes from crypto.getRandomValues with rejection sampling, and the strength figure is calculated from the pool you actually selected.
Length stays between 8 and 64: 8 is the minimum most sites still accept, and past 64 some sites quietly truncate the password, so longer is not safer here.
The look-alike toggle removes exactly these six characters from every source, custom characters included: I, l, 1, O, 0 and |. One of each puts at least one character from every selected class into each password.
Whatever you type here joins the character pool and is counted in the entropy below, but it is never saved to storage.
Labels: Weak below 45 bits, Fair 45–63, Good 64–79, Strong from 80 up.
Enforcing "at least one of each selected class" makes the draws slightly non-uniform, so the bit count above is a mild over-estimate, never an under-estimate.
Random values come from crypto.getRandomValues — the browser CSPRNG — with rejection sampling to avoid modulo bias. Math.random is never used.
Nothing yet. Press Generate.
Never reuse one of these for an account you already have a password for. Generate each password once, store it in a password manager, and let the manager fill the form.
This page has no server code and makes no request: a password exists only in your tab, is shown once, and is never stored, logged or sent anywhere. Only your length and toggle settings are kept on this device.
The honest limit: a compromised device or a keylogger still wins, because it sees whatever you can see and copy. Keep the operating system and antivirus current, and enable two-factor authentication on important accounts.
How to use
- Set the Length (8 to 64) and How many (1 to 20), then switch on the character classes you need: lowercase, uppercase, digits and symbols.
- Optionally turn on No look-alikes to drop I, l, 1, O, 0 and |, keep One of each to guarantee every class appears, or add your own characters to the pool.
- Press Generate and read the pool size, the bits of entropy and the Weak, Fair, Good or Strong label under the controls.
- Use Show or Hide per password, then Copy the one you want. Press Regenerate for a fresh set, or Clear to remove them from the page.
Frequently asked questions
Are the passwords really random and kept private?
They come from crypto.getRandomValues, the browser’s cryptographic random source, and unbiased rejection sampling picks each character; Math.random is never used. A generated password lives only in this tab: nothing is stored, logged or sent anywhere, and only your length and toggle settings are kept on this device.
How long should a password be?
For an account protected only by a password, 16 characters with several character types is a sound default, which is about 100 bits of entropy. The tool stops at 64 because some sites silently truncate longer passwords. Use a password manager so each account gets its own unique password.
Why does the entropy figure say it may be an over-estimate?
Forcing at least one character from every selected class makes the draw very slightly less uniform than a pure random pick, so the displayed bits are a mild over-estimate rather than an under-estimate. Strength labels are Weak below 45 bits, Fair 45 to 63, Good 64 to 79 and Strong from 80.
Guides
Related tools
Image Compressor & Resizer
Shrink JPG, PNG and WebP files by adjusting quality and maximum width. Processing stays on your computer, so private images never leave it.
Image Resizer
Resize one or more images to exact pixels or a percentage, with the aspect ratio locked and no surprise re-compression. Runs on your device, no upload.
Image Format Converter
Convert images between PNG, JPG, WebP and AVIF in your browser, keeping the original size. A quality slider plus an honest check of what your browser encodes.