Password Generator

Strong passwords made here, on a page that cannot send them anywhere.

Runs entirely in your browser

Loading the tool…

Characters
  • —Bits of entropy each
  • —Characters to choose from
  • —Strength
Passwords

  

Nothing here is stored, and nothing goes in the address bar. Close the tab and these are gone for good.

Every password here is drawn character by character from crypto.getRandomValues, which is your operating system's cryptographic generator rather than the ordinary random function. The drawing is done in WebAssembly compiled from Rust, in this tab, on your machine.

This page cannot send them anywhere, and that is checkable. It is served with a Content-Security-Policy header whose connect-src is none, which means the browser refuses to let it open a connection to any address at all, including back to this site. Look at the response headers, or open the network tab and generate a hundred. You are not being asked to trust anybody.

Nothing is stored either. The passwords are not written to the address bar, so they never enter your history, and nothing is kept in the browser's storage. Close the tab and they are gone.

Length beats cleverness. The bit count above is worked out from how the password was made, the size of the alphabet raised to the length, not guessed at by looking at the result. Substituting a 3 for an E adds almost nothing, because every attacker's software already knows that trick. Adding four more characters roughly multiplies the work of guessing by a million.

How to use it

  1. Choose a length and how many you want. Twenty characters is a good default.
  2. Turn character types on or off. The entropy figure updates as you do.
  3. Press Copy, and paste it straight into your password manager.

Questions

How do I know the password is not being sent somewhere?

Because the browser will not let the page do it. Every page here is served with a Content-Security-Policy whose connect-src is none, so a request to anywhere is refused before it is made. That is visible in the response headers and in the network tab, and it does not depend on believing a privacy policy. There is also no server on the other end: the site is static files.

How long should a password be?

Twenty random characters is comfortably beyond what is worth attacking, at around 120 bits. Sixteen is fine for most things. The number that matters is the entropy shown above rather than the length alone, because a longer password from a smaller alphabet can be worth less than a shorter one from a larger.

Do symbols and mixed case actually help?

They widen the alphabet, which helps, but far less than length does. Going from lowercase-only to everything roughly doubles the work per character; adding four characters multiplies it by about a million. If a site refuses symbols, add length instead and lose nothing that matters.

Is the clipboard safe?

It is the weakest part of this and worth knowing about, because it is outside what any web page controls. Windows keeps a clipboard history, macOS shares the clipboard across your devices, and Android syncs it too. Paste into your password manager promptly, and copy something else afterwards.

Could a browser extension see it?

Yes. Any extension with permission to read the page can read anything on it, and that is true of every password generator on the web, including the web interface of a password manager. If you are generating something important, a private window with extensions disabled removes the question.

Should I use this or my password manager's generator?

Your password manager's, when you have one. Not because it is more random, but because it generates and saves in one step with no copy and paste in the middle, and the trip through the clipboard is where a password is most likely to be seen. This page is for when you do not have one to hand, or want something outside it.

Why is there no strength checker for a password I already have?

Because a page that invites you to type your real passwords into it is teaching a habit that will hurt you somewhere else. This one is safe, but the next site that asks will not be, and the difference is not visible from the outside. This tool only makes passwords; it never receives one.

Your data stays on your device

Everything above runs inside your browser as WebAssembly compiled from Rust. Nothing you type is uploaded, logged or stored on a server. You can load this page once, go offline, and it still works.

This page makes no requests at all, to anywhere. That is not a promise in the copy: it is a Content-Security-Policy header your browser enforces, and connect-src on it is none. Open the network tab and watch nothing happen.