Strong Password Generator — Random Passwords & Passphrases
Generate a strong random password, a memorable passphrase or a PIN. Runs entirely in your browser, nothing is sent or stored.
Excellent · about 126 bits of entropy
Generated in your browser with crypto.getRandomValues, the same randomness source browsers use for encryption keys. Nothing is sent to us, stored, or logged, and no password appears in the page address. You can disconnect from the internet and this still works.
Found a problem, or something that could be better? We read every message and we fix things quickly.
This free password generator creates strong random passwords, memorable passphrases and PINs directly in your browser. Nothing is transmitted, nothing is stored, and nothing is logged: the password exists only on your screen until you copy it. You can disconnect from the internet and the tool still works, which is the simplest proof that it is not sending your password anywhere.
Randomness comes from crypto.getRandomValues, the browser's cryptographic random number generator, and not from Math.random. That distinction matters more than any option on this page. Math.random is predictable enough that an attacker who sees a few outputs can reconstruct the sequence, which makes any password built from it worthless. Every character here is drawn without modulo bias, so each one is genuinely as likely as any other.
How to use
- Choose a type: a random password for anything stored in a password manager, a passphrase for the few passwords you must type from memory, or a PIN for a device.
- Set the length. For a random password, 16 characters or more; for a passphrase, 7 words or more, since a short passphrase is weaker than it looks.
- Adjust the character sets if a site rejects symbols, or turn on 'avoid lookalikes' if you will be typing or reading the password aloud.
- Check the entropy figure under the bar. Aim for 80 bits or more; that is the number that actually describes how hard the password is to guess.
- Copy it, and paste it straight into your password manager. Do not email it to yourself or keep it in a note.
Frequently asked questions
Is this password generator safe to use?
The password is created in your browser by crypto.getRandomValues, the same randomness source browsers use to generate encryption keys. It is never sent over the network, never stored, never written to the page address and never logged. You can verify this by disconnecting from the internet: the generator keeps working. The one risk with any online generator is the page itself being tampered with, which is why a password manager's built-in generator is still the safest option for your most critical accounts.
How long should a password be in 2026?
For a password stored in a password manager, 16 characters or more of random text. NIST's SP 800-63B revision 4 recommends a minimum of 15 characters where a password is the only authentication factor, and says systems should accept at least 64. Length does far more work than complexity: a 16-character lowercase-only password is considerably harder to guess than an 8-character password with mixed case, digits and symbols.
Are passphrases better than random passwords?
They are better for the handful of passwords you have to type from memory, such as your device login and your password manager's master password. NIST explicitly endorses passphrases. A seven-word passphrase from this tool's 1,169-word list is about 71 bits, easy to remember and hard to guess, whereas a 20-character random string is neither. For everything else, use a random password and let the manager remember it.
What does the entropy score mean?
Entropy in bits is a measure of how many guesses an attacker would need. Each additional bit doubles that number. Under 45 bits is weak against an offline attack on a leaked password database; 80 bits is comfortable; above 100 bits is beyond any foreseeable brute-force effort. It is a more honest measure than the usual coloured strength meter, which often rewards 'P@ssw0rd!' for containing a symbol while missing that it is one of the most-guessed passwords in existence.
Should I change my passwords every 90 days?
No, and NIST now advises against it. Forced periodic rotation pushes people toward small predictable changes (Summer2025, Summer2026) that are easier to guess, not harder. The current guidance is to use a long unique password per account and change it only when there is evidence of compromise, such as a breach notification.
Do I still need a password manager if I use this?
Yes. A generator solves one problem: creating a password that is hard to guess. A manager solves the harder one: having a different strong password for every account without needing to remember any of them. Generating a strong password and then reusing it everywhere leaves you exposed the moment any one of those sites is breached.
Length beats complexity, and the maths is not close
The old advice, one uppercase, one number, one symbol, came from an era when passwords were short. It produces passwords people cannot remember and attackers can predict, because everyone satisfies the rule the same way: capitalise the first letter, put the digit and the exclamation mark at the end.
Compare the actual guess space. An 8-character password using upper, lower, digits and symbols has around 52 bits of entropy. A 16-character password using only lowercase letters has around 75 bits. The second is roughly eight million times harder to guess, and it is easier to type.
This is why NIST's SP 800-63B revision 4 dropped mandatory composition rules and raised the length recommendation instead. If you take one thing from this page, make your passwords longer rather than more decorated.
Which type to use, and when
• Random password, 16 to 24 characters: everything stored in a password manager, which is almost every account you have. You never type these, so length costs you nothing.
• Passphrase, 7 words or more: the two or three passwords you must type from memory. Word-list size matters, so check the bit count rather than trusting the word count. Your password manager's master password, your laptop login, your phone backup.
• PIN: device unlock only, where the hardware limits how many attempts an attacker gets. A 6-digit PIN has about 20 bits of entropy, which is hopeless against an offline attack and perfectly adequate against someone holding your phone with three tries.
What a generator cannot fix
A strong password protects one account. It does nothing about the three failure modes that cause most real compromises: reusing the same password across sites, so one breach unlocks the rest; phishing, where you hand the password over yourself; and the absence of a second factor, which is what stops a stolen password from being enough.
Turn on two-factor authentication wherever it is offered, prefer an authenticator app or a passkey over SMS, and use a different password everywhere. A generator is one part of that, not a substitute for it.
For a business, the same logic applies at a larger scale: unique credentials per person, least-privilege access, and a way to revoke someone's access in one place when they leave. That is the access-control work we do as part of cloud infrastructure and cybersecurity engagements.
Related free tools
- Favicon Generator — Turn any logo into a complete favicon package — favicon.ico, all PNG sizes, Apple touch icon, and webmanifest — in one click.
- Online Calculator — A clean, iPhone-style calculator that works with your keyboard and numpad. Percent, sign, history, copy — no ads, nothing installed.
- Test File Generator — Generate a dummy file of any exact size in your browser — 1 KB to 2 GB, random bytes, text, CSV or JSON.