Email accounts
Your email is the master key to every other account. Give it 20+ characters or a 6+ word passphrase.
Create strong random passwords and memorable passphrases. Uses your browser's built-in cryptographic random number generator — everything happens on your device. Nothing is uploaded.
Many simple password generators use Math.random(), which is predictable enough that an attacker who sees a few outputs can sometimes work out the next ones. This generator uses crypto.getRandomValues() instead — the browser's cryptographic random number source. It is the same source used to generate encryption keys, and it is designed to be unpredictable.
Password strength is not about how complex the password looks. It is about how many possibilities an attacker has to try. That is measured in bits of entropy:
Entropy = log₂ (charset size) × length
Each extra bit doubles the search space. A password with 40 bits has about 2⁴⁰ ≈ 1 trillion possible combinations. A password with 80 bits has about 2⁸⁰ ≈ 1 octillion.
The estimate assumes an attacker can try 10 billion passwords per second. That is the realistic speed of a modern GPU-based cracking rig against a fast hash. Against strong hashes like bcrypt or Argon2, the real number is far slower — so treat these estimates as a worst case.
When "guarantee at least one of each" is enabled, the generator places one character from each selected set first, then fills the rest randomly, then shuffles the whole password. This ensures the result always contains at least one lowercase, uppercase, digit and symbol — as many sites require — without weakening the randomness.
A passphrase is a sequence of random words. The entropy depends on how many words are chosen and how big the word list is:
Entropy = log₂ (word list size) × word count
The word list used here has 256 entries, so each word contributes 8 bits. A 6-word passphrase has about 48 bits of entropy — enough for most personal accounts but not for high-value targets. A 10-word passphrase reaches 80 bits. For critical accounts like email or banking, add extra words or combine a passphrase with a stored password manager.
| Length | Charset | Entropy | Strength |
|---|---|---|---|
| 8 | lowercase only | 37.6 bits | Fair |
| 8 | full ASCII (95) | 52.5 bits | Fair |
| 12 | lower + upper + digits | 71.4 bits | Strong |
| 16 | lower + upper + digits | 95.3 bits | Very strong |
| 16 | lower + upper + digits + symbols | 104.9 bits | Very strong |
| 20 | lower + upper + digits + symbols | 131.1 bits | Excellent |
| 24 | lower + upper + digits + symbols | 157.3 bits | Excellent |
| 4-word passphrase | 256-word list | 32 bits | Weak |
| 6-word passphrase | 256-word list | 48 bits | Fair |
| 8-word passphrase | 256-word list | 64 bits | Strong |
| 10-word passphrase | 256-word list | 80 bits | Very strong |
Your email is the master key to every other account. Give it 20+ characters or a 6+ word passphrase.
Use a unique password for each financial account. Never reuse a password across banks.
Most password managers have a built-in generator. Use this one when you need to generate a master password, or when you want to generate one without signing in anywhere.
Generate a strong Wi-Fi password and hand it out on paper or in person. The "exclude similar" option makes it easy to read aloud.
Long random strings for API keys, database credentials, JWT secrets and other machine-to-machine passwords.
Team accounts, streaming services, shared inboxes. Generate once, share via a secure channel, change periodically.
Yes. The generator uses the browser's built-in cryptographic random number generator (crypto.getRandomValues). Passwords are never uploaded, logged or shared. The entire calculation runs on your device.
For most accounts, 16 characters with mixed character sets is very strong. For high-value accounts like email or banking, use 20+ characters or a 6-word passphrase.
A passphrase is several random words strung together, like correct-horse-battery-staple. They are easier to remember than random characters but still provide strong security if the words are truly random.
Entropy is a measure of unpredictability, measured in bits. Each extra bit doubles the number of possible combinations. 80 bits is considered strong; 100 or more is very strong.
Both can be equally strong — it depends on length and randomness. A 6-word passphrase from a large word list has more entropy than an 8-character password, and it is easier to remember. But for the strongest protection, use a password manager with a randomly generated password.
No. Passwords are generated in your browser and never leave your device. Nothing is uploaded, saved or logged.
It removes characters that are easily confused, such as l (lowercase L), 1 (one), I (uppercase i), and 0 (zero) versus O (uppercase o). This makes passwords easier to read aloud or type from paper.
Never. If one site is breached, attackers try the same email/password combination on hundreds of other sites. Use a unique password for every account, and a password manager to remember them all.
Last updated: .