Password Generator
Generate a strong, random password with configurable length and character sets — uppercase, numbers and symbols.
Strong
101 bits of entropy rates as "Strong" — each extra bit doubles the number of guesses an attacker would need to try.
- Estimated Entropy101 bits
Generated fresh each time you calculate — nothing is stored or sent anywhere. Use a password manager to save it.
About the Password Generator
The moment this gets used is almost always the same one: a signup form just rejected "password123" and demanded something stronger, or a security prompt is nagging you to update an old, reused password. Rather than typing something memorable and hoping it's strong enough, this generates a genuinely random string from whatever character sets you choose — lowercase, uppercase, numbers, symbols — at a length you control.
Everything happens in your browser. The password is generated locally using your browser's cryptographic random number generator and never touches a server, which matters more than it sounds — a password worth generating randomly is also a password worth not transmitting anywhere, even to the site that's supposedly helping you create it.
Nothing is saved either, by design: refresh the page or hit calculate again and the previous password is gone for good, so the plan should always be to copy it straight into a password manager rather than relying on this page to remember it for you.
How it’s calculated
Each character is drawn independently and uniformly from the combined pool of the character sets you've enabled, using the browser's crypto.getRandomValues API where available — a cryptographically secure source, unlike Math.random(), which isn't designed to resist prediction.
Strength is reported as entropy in bits, calculated as length × log2(pool size): a longer password or a larger character pool both increase it. Each additional bit doubles the number of guesses a brute-force attack would need on average, which is why length matters more than most people expect — going from 8 to 16 characters increases the guess space far more than adding a couple of symbols to an 8-character password ever could.
Frequently asked questions
How long should a password be?
12 characters is a reasonable practical minimum today, and 16 or more is comfortably strong for most purposes; length increases entropy faster than adding more character types does, so a longer password with fewer symbol types often beats a short one stuffed with special characters.
Is this password generator actually secure?
It uses your browser's cryptographically secure random number generator (crypto.getRandomValues) rather than a predictable pseudo-random function, and the password is never sent to a server — it exists only on your device until you copy it elsewhere.
What does 'bits of entropy' actually mean?
It's a measure of how many possible passwords could have been generated with your chosen length and character set — expressed as a power of two, so higher bits mean an attacker guessing at random would need to try exponentially more combinations before finding yours.
Should every account have a different password?
Yes — reusing a password means a breach at one site exposes every other account that shares it. A password manager makes using a unique, random password like this one for every account practical without having to memorize them.
Why avoid password patterns like 'Name1234!'?
Patterns based on real words, names or predictable substitutions are exactly what password-cracking tools test first — they cut the effective search space enormously compared to a truly random string of the same length, even though the two might look similarly complex at a glance.
Related calculators
Powered by GetCalculator.online