Secure Password Generator

Runs in your browserSecurity#Utility

Strong random passwords, passphrases, PINs, API keys and tokens, made securely in your browser.

Remove any symbol a website doesn't accept.

1 to 100

StrengthVery strong102 bits of entropy

Offline attack at 10 billion guesses a second: centuries to try every combination.

    Copied passwords can stay in your clipboard history (Windows + V, phone keyboards). Clear it after pasting.

    How to use, limits & privacy

    About Secure Password Generator

    Generate strong random passwords, easy-to-type passphrases, and PINs, API keys and tokens. Everything is made in your browser with the Web Crypto random number generator, and each value shows its entropy in bits and how long an offline attack would take. It also works as a random string generator: pick hex, base64url, NanoID-style IDs or your own characters, and make up to 100 at once.

    How to Use

    1

    Choose what to make

    Pick Password, Passphrase, or PIN & tokens. A new value appears straight away and changes whenever you change a setting.

    2

    Adjust the settings

    Set the length or number of words, the characters to use, and How many values you need (1 to 100). Turn on Exclude look-alikes if the password will be typed by hand.

    3

    Copy or download

    Click the copy icon next to a value, Copy all for a list, or Download .txt to save them. Click Generate for a fresh set.

    Privacy & Processing

    • Mode: local
    • Files Leave Browser: Local tool processing; review details below
    • Max Input Size: Device memory limits
    • Account Required: No
    • Data Stored Locally: Nothing is saved; values disappear when you close or reload the page.
    • Network Processing: Assets or models may require an initial download

    Passwords, passphrases and tokens are generated in your browser and never sent anywhere. Passphrase words come from the EFF short word list by Joseph Bonneau and the Electronic Frontier Foundation, licensed CC BY 4.0.

    Rules & Limitations

    • Passwords are 4 to 128 characters and always include at least one of each character type you turn on.
    • Passphrases use 3 to 10 words from the EFF short word list (1,296 words). Capitalising every word adds no strength; Add a number adds a little.
    • Custom characters are read as whole characters, so emoji and Hindi letters work, and repeated characters are counted once.
    • Copied values can stay in your clipboard history (Windows + V, phone keyboards and clipboard apps). Clear it after pasting.
    • Nothing is saved. Store passwords in a password manager, not in a text file you keep.

    Top Suggestions

    • Creating a new password for email, banking or UPI apps
    • A passphrase you can remember for a password manager or laptop login
    • A random 4-digit or 6-digit PIN, or test OTPs
    • API keys, secrets and tokens for developers (hex, base64url, NanoID-style IDs)
    • Bulk random strings or codes for test data and coupon codes

    Secure Password Generator FAQ

    How do I generate a strong password?

    Keep the default Password settings: 16 characters with upper case, lower case, digits and symbols. That is about 100 bits of entropy, far beyond what any attacker can guess. If a site rejects some symbols, remove them from Symbols to use.

    Is this password generator safe to use?

    Yes. Values are made in your browser with crypto.getRandomValues, the browser's cryptographic random number generator, and are never sent or stored. Unbiased sampling means every character is equally likely.

    What is the difference between a password and a passphrase?

    A password is random characters; a passphrase is random words such as Rail-Blast-Anger-Claw-Royal. Five random words from the EFF list give about 52 bits and six give about 62, and they are much easier to type and remember. Use more words for anything important.

    How do I generate a random string, API key or PIN?

    Choose PIN & tokens, then pick a format: a 4-digit PIN, a 6-digit PIN or OTP, a 128-bit or 256-bit hex key, a letters-and-digits token, a 256-bit base64url token, a NanoID-style ID, or Custom characters with any length up to 128.

    What does entropy in bits mean?

    It measures how many possible values the settings can produce: each extra bit doubles the guesses an attacker needs, assuming they know exactly how the value was made. Here, under 27 bits rates Weak or worse, 40 to 53 bits Strong and over 53 bits Very strong; keys should have 128 bits or more.

    Are the generated passwords saved or uploaded?

    No. Nothing leaves your device and nothing is stored. Remember that copied passwords can stay in your clipboard history until you clear it.