Secure Password Generator
Strong random passwords, passphrases, PINs, API keys and tokens, made securely in your browser.
Offline attack at 10 billion guesses a second: centuries to try every combination.
Copied passwords can stay in your clipboard history (Windows + V, phone keyboards). Clear it after pasting.
Secure Password Generator FAQ
How do I generate a strong password?
Keep the default Password settings: 16 characters with upper case, lower case, digits and symbols. That is about 100 bits of entropy, far beyond what any attacker can guess. If a site rejects some symbols, remove them from Symbols to use.
Is this password generator safe to use?
Yes. Values are made in your browser with crypto.getRandomValues, the browser's cryptographic random number generator, and are never sent or stored. Unbiased sampling means every character is equally likely.
What is the difference between a password and a passphrase?
A password is random characters; a passphrase is random words such as Rail-Blast-Anger-Claw-Royal. Five random words from the EFF list give about 52 bits and six give about 62, and they are much easier to type and remember. Use more words for anything important.
How do I generate a random string, API key or PIN?
Choose PIN & tokens, then pick a format: a 4-digit PIN, a 6-digit PIN or OTP, a 128-bit or 256-bit hex key, a letters-and-digits token, a 256-bit base64url token, a NanoID-style ID, or Custom characters with any length up to 128.
What does entropy in bits mean?
It measures how many possible values the settings can produce: each extra bit doubles the guesses an attacker needs, assuming they know exactly how the value was made. Here, under 27 bits rates Weak or worse, 40 to 53 bits Strong and over 53 bits Very strong; keys should have 128 bits or more.
Are the generated passwords saved or uploaded?
No. Nothing leaves your device and nothing is stored. Remember that copied passwords can stay in your clipboard history until you clear it.