Password Generator

Generated entirely in your browser using a cryptographically secure random source — your password is never sent anywhere.

What makes a password strong?

Password strength comes primarily from length and character variety. Each additional character multiplies the number of possible combinations an attacker would need to guess, so a longer password with a mix of uppercase, lowercase, numbers, and symbols is exponentially harder to crack than a short one, even if the short one looks "complex."

Frequently asked questions

Is this password sent over the internet or stored anywhere?

No. The password is generated entirely in your browser using the Web Crypto API's cryptographically secure random number generator. It never leaves your device or gets sent to any server.

How long should my password be?

NIST's current password guidelines (SP 800-63, revised 2025) recommend at least 15 characters if the password is your only login step, or 8+ characters when it's paired with multi-factor authentication. Longer is generally better, and using a unique password per account — ideally managed by a password manager — matters just as much as length.

Should I include symbols?

Yes, when the site allows it — symbols expand the character set an attacker has to search, increasing strength. Some sites restrict which symbols are allowed, so if a generated password gets rejected, try regenerating without symbols.