๐ Password Generator
Create a strong, random password using your browser's secure random number generator โ nothing is sent anywhere.
About Password Generator
This tool generates random passwords you control the composition of: total length from 6 to 64 characters, and separate toggles for uppercase letters, lowercase letters, numbers, and symbols. It's meant for creating new account passwords, API keys used as shared secrets, or WiFi passwords โ anywhere you need something unpredictable rather than something memorable.
Randomness comes from the Web Crypto API's crypto.getRandomValues() method, seeded by your operating system's cryptographically secure random number generator โ the same category of source used to generate encryption keys. That's a meaningful difference from Math.random(), which many hand-rolled password generators use and which is fast but not designed to resist prediction.
The live strength meter reflects the character pool size and length you've chosen, not a check against known-breached password lists โ a 20-character password built only from lowercase letters is still weaker, bit for bit, than a 14-character one mixing all four character types. The exclude-ambiguous-characters option removes visually similar characters (I, l, 1, O, 0) so a password is easier to transcribe correctly when typing it by hand rather than pasting it.
Frequently asked questions
Is this password sent to a server?
No โ it's generated entirely in your browser using the Web Crypto API's secure random number generator, and never transmitted anywhere.
How long should my password be?
Most security guidance recommends at least 12โ16 characters, mixing letters, numbers, and symbols โ longer is generally better than more complex.
What does the strength meter actually measure?
It estimates entropy from the password's length and the character sets you've enabled โ more characters and more variety mean more possible combinations for an attacker to guess.
Why exclude ambiguous characters like I, l, 1, O, 0?
These characters look alike in many fonts, so excluding them makes a password easier to type correctly when you're reading it off a screen or copying it by hand.
Is Math.random() good enough for generating passwords?
No โ it's not cryptographically secure and its output can theoretically be predicted. This tool uses crypto.getRandomValues() instead, which draws from the operating system's secure random source.