Password Generator
Random passwords made with the browser crypto API. Generated passwords are not recorded.
Stays in your browserWeb Crypto APIAs of 2026.10.03
Generated passwords
Generated passwords are not recorded. Save them in a password manager right away. They are gone when you leave or reload this page.
How to use Password Generator
- 1Set the length (4 to 128) and choose the character types. New passwords appear right away.
- 2Check the strength under the list. Press Regenerate if you want different passwords.
- 3Press the copy button next to a password, then save it in a password manager.
Password Generator options
- Length
- 4 to 128 characters. The default is 16.
- Character types
- Uppercase (26), lowercase (26), digits (10), and symbols (32). All four are on by default, and at least one stays selected.
- Exclude look-alikes (I l 1 O 0)
- Leaves out the five characters that are easy to confuse: uppercase I, lowercase l, digit 1, uppercase O, and digit 0.
- At least one of each type
- On by default. Every password gets at least one character from each selected type, and the positions are shuffled afterwards.
- Count
- 1 to 100 passwords at a time. The default is 5.
How the passwords are made
Every character is picked with crypto.getRandomValues from the Web Crypto API. The tool asks for 32-bit random numbers and maps them to the list of allowed characters. A plain remainder would make the first few characters of the list slightly more likely, so numbers from the uneven top of the range are discarded and drawn again. This is called rejection sampling.
When “At least one of each type” is on, the tool first picks one character from each selected type, fills the remaining positions from all allowed characters, and then shuffles the positions with the Fisher–Yates method using the same random source. Without the shuffle, the first positions would always follow the same order of types.
Reading the strength
The number under the list is the entropy: length × log2(number of possible characters). Each extra character adds the same amount, so length matters more than adding one more character type. A password of 16 characters from all 94 has 104.9 bits; 20 letters and digits have 119.1 bits.
Password Generator examples
Default settings: 16 characters chosen from 94
Entropy in bits. 80 to 127 bits is shown as Strong.
Input
16 × log2(94)
Output
104.9
20 characters, letters and digits only (62)
Entropy in bits. Without symbols, a longer password gives more entropy than the default.
Input
20 × log2(62)
Output
119.1
Examples use the reference cases this tool is tested against.
Password Generator: frequently asked questions
Is my input sent to a server?
No. Your input and the result are processed only in this browser and are not stored. Reloading the page clears them.
Are the generated passwords saved anywhere?
Generated passwords are not recorded. Save them in a password manager right away. They exist only on this page and are gone when you leave or reload it, which is also why there is no download button.
How random are the passwords?
Each character is chosen with crypto.getRandomValues, the cryptographic random source of the browser. A random value that would make some characters more likely is thrown away and drawn again (rejection sampling), so every character has the same chance. Math.random is not used.
What does the strength number mean?
It is the entropy in bits: length × log2(number of possible characters). Below 50 bits is Weak, 50 to 79 is Fair, 80 to 127 is Strong, and 128 or more is Very strong. The default of 16 characters from 94 gives 104.9 bits.
What if a site does not accept symbols?
Turn off Symbols and make the password longer. 20 letters and digits give 119.1 bits, more than the default 16 characters with symbols.
Related tools
How it works · Standards
- Processed in: this browser (your device). Nothing is sent or stored.
- Standards: Web Crypto API
- Engine: Web Crypto API (crypto.getRandomValues) (browser built-in) · ZEKILO Dev password generator (in-house code)
- The strength figure assumes every character is chosen at random. It does not describe a password you edit by hand.
- Use a different password for every account.
- As of 2026.10.03
- Changelog: 2026.10.03 First release