Random Password Generator

Crypto-strong passwords with per-set guarantees and an honest entropy rating — nothing leaves your browser.

How to use

  1. Set the length (4–128) and toggle the character sets.
  2. A password generates instantly and re-rolls on every change.
  3. Copy it straight into your password manager.

Frequently asked questions

How strong are these passwords?

They come from crypto.getRandomValues with unbiased sampling. Entropy depends on length and pool size — shown under the password in bits. At 16 characters with all sets enabled that is roughly 100 bits, far beyond offline cracking reach for any realistic attacker.

Why guarantee one character per selected set?

Many password policies require at least one lower, upper, digit and symbol. Pure chance occasionally omits a class (especially at short lengths), so the generator seeds one character from each selected set, then shuffles so the guarantee is invisible in the result.

What makes a password “weak” in the label?

Only entropy math: length × log2(pool size). Below 30 bits (e.g. 4 characters) is trivially brute-forced; 50–75 bits resists casual attacks; 100+ bits is out of reach for everything but nation-state budgets.

Are these passwords sent anywhere?

No. Generation happens in your browser tab with the Web Crypto API — nothing is transmitted, logged or stored. Close the tab and the password exists nowhere else.

Should I still use a password manager?

Yes — a generator makes strong passwords; a manager remembers them uniquely per site. Generate here, paste into your manager, and never reuse passwords across accounts.

Comments