SECURITY TOOL
Password Generator
Create strong, cryptographically secure passwords locally in your browser. Nothing is uploaded or stored.
PRIVATE BY DESIGN
Create a secure password
Generated with your browser’s cryptographic random number generator.
Select at least one character set.
Password generator guide
A strong password helps protect an account if another service suffers a breach. This generator creates random passwords using your browser’s cryptographically secure random number generator — no pattern, no dictionary words, no reuse, and nothing sent to any server.
The default mode uses only the symbols nearly every website accepts (! @ # $ % & ?). If you are dealing with a site that accepts a wider range of symbols, enable the extended symbol set for additional character variety.
How password strength actually works
Password strength is measured in entropy — the number of possible combinations an attacker would have to try. Each extra character multiplies the search space; each character type adds a smaller but still meaningful multiplier.
Length dominates. A 16-character password with only lowercase letters has roughly 75 bits of entropy; a 12-character password using all four character types has about 78. In practice, an 8-character password is crackable in hours on modern hardware, while 14+ characters with mixed types is effectively unbreakable by brute force.
That is why this tool defaults to 16 characters and why the entropy meter updates live as you adjust the length and character sets — it is showing you the actual math, not a made-up score.
Why "correct horse battery staple" thinking is still valid
Random characters are great, but humans remember passphrases better. A passphrase of 4–6 random words (using a tool like diceware) gives comparable entropy to a random 12-character string — and you can actually type it from memory.
Whichever route you take, the rules are the same: never reuse a password across sites, never use personal information (names, birthdays, pet names), and treat any password you have typed into a sketchy website as compromised.
When the extended symbol set makes sense
The extended symbol set (!@#$%^&*()-_=+[]{};:,.<>?/|~) adds roughly 12 bits of entropy at 16 characters — real, but not transformative. Use it for high-value accounts where you know the site accepts all symbols: password managers, email, banking, hosting panels.
For everything else, the default set is the sweet spot: still strong, and it will not get rejected by a legacy system that bans braces, pipes, or angle brackets. A password that gets rejected by the site’s form is worse than one with slightly fewer symbols.
Storing your passwords
The only practical way to use truly random passwords across dozens of sites is a password manager. It generates, stores, and autofills them, and it remembers which site expects which character set. Bitwarden, 1Password, and KeePass are all solid choices.
If you must store passwords in a file, use an encrypted container (VeraCrypt, or the encrypted notes feature of a password manager) — never a plaintext spreadsheet or text file.
Frequently asked questions
Are the generated passwords truly random?
Yes. The generator uses crypto.getRandomValues(), the browser’s cryptographically secure random number generator — the same source used for encryption keys. It is not Math.random().
How long should a password be?
At least 12 characters for everyday accounts, 16 or more for anything important. Length matters more than which character types you include.
Is my password sent to a server?
No. Everything runs locally in your browser. The password is generated on your device and never transmitted anywhere.
Why do some websites reject my password?
Many sites restrict which symbols they accept. The default mode of this tool uses only ! @ # $ % & ? — characters almost universally allowed. If a site still rejects it, untick Symbols entirely.
Should I use a password manager?
Yes — it is the only realistic way to use unique random passwords for every account. A password manager with a master password is safer than reusing one password everywhere.
How can I check whether a password generator is trustworthy?
Prefer a generator that works client-side and clearly explains how it handles your input. You can verify this by testing it offline or inspecting the browser network panel. Do not use a generator that sends generated passwords to a server.
Privacy note: password generation, entropy calculations, and copying happen in your browser. Generated values are not submitted to NAB Tools.