Password Generator
Weak or reused passwords are one of the easiest ways for an account to be compromised. This password generator creates a strong, random password in your browser — choose the length and which character types to include, then generate as many times as you like. Nothing is sent anywhere or stored; the password exists only on your screen until you copy it.
Select at least one character type (uppercase, lowercase, numbers or symbols).
How to Use the Password Generator
- Set the password length (16 or more is a good default for most accounts).
- Choose which character types to include — uppercase, lowercase, numbers and symbols.
- Optionally exclude ambiguous characters if you'll need to read or type the password manually.
- Select Generate. Copy the result or generate again for a different password.
Every click of Generate produces a brand-new password — there's no limit, so keep generating until you have one you're happy with. If a site has specific rules (for example, requiring a symbol, or not allowing certain characters), adjust the character-type checkboxes to match before generating.
Password Generator — How It Works
The generator builds a pool of allowed characters from the types you select, then uses your browser's Web Crypto API (crypto.getRandomValues) to pick a cryptographically secure random character from that pool for each position in the password. This is a materially stronger source of randomness than Math.random(), which is not designed to be unpredictable and should not be relied on for anything security-related.
The strength estimate shown is based on the password's entropy — the length multiplied by the log₂ of the character pool size — which reflects how many attempts a brute-force guess would need on average.
When to use this tool
Use this whenever you need a new password for an account, a Wi-Fi network, or anywhere else a strong, unpredictable value is useful — and you don't want to reuse a password from another account.
Key Features & Benefits of This Password Generator
- Cryptographically random — uses the Web Crypto API, not a predictable pseudo-random function.
- Nothing stored or sent — runs entirely in your browser; the password is never transmitted anywhere.
- Customisable — choose length and exactly which character types to include.
- Works on any device — mobile or desktop, no app or installation needed.
Good to know
A strong, unique password is most effective when paired with a password manager, so you don't need to remember it, and with two-factor authentication where a site offers it. Avoid reusing any generated password across more than one account.
Password Generator — FAQs
How random is this password generator?
It uses your browser's cryptographically secure random number generator (Web Crypto API), the same class of randomness used for security-sensitive tasks, rather than an ordinary pseudo-random function.
Is my password sent anywhere or stored?
No. The password is generated entirely in your browser. Nothing is transmitted to a server, logged, or saved, and it disappears when you close or refresh the page.
How long should my password be?
Longer is stronger. 12 characters is a reasonable minimum for most accounts; 16 or more is better for anything sensitive, such as email, banking, or a password manager's master password.
What does excluding ambiguous characters do?
It removes characters that are easy to misread or mistype, such as 0 and O, or 1, l and I, which is useful if you'll be reading the password aloud or typing it from a printed copy.