Toolkit
Developer tools

Password Generator

Generate strong random passwords and passphrases.

Type
Generated

—

Weak — roughly 0 bits of entropy. Increase the length or add another character set.

About this tool

Generate random passwords from a character set you control, or word-based passphrases that are far easier to type on a phone. Entropy is shown in bits so you can judge strength by arithmetic rather than by a colour bar.

How to use it

  1. Choose a password or a passphrase.
  2. Set the length and which character sets to include.
  3. Generate, then copy — nothing is stored or logged.

What entropy actually measures

Entropy is how many guesses an attacker needs, expressed as a power of two. A password with 60 bits of entropy needs up to 2^60 guesses — about a quintillion.

It is a property of how the password was generated, not how it looks. This is the part that trips people up:

Password Looks Actual entropy
P@ssw0rd! Strong ~20 bits — it is a dictionary word with predictable substitutions
correct-horse-battery-staple Weak ~44 bits if the words were chosen randomly
x7#mK9$pL2@qR4 Strong ~85 bits

Substituting 3 for e and adding a trailing exclamation mark adds almost nothing. Cracking tools apply those same substitutions automatically — they were the first thing anyone thought to automate.

How much do you need?

  • Below 50 bits — crackable by a motivated attacker with commodity hardware
  • 75 bits — comfortable for an online account that has rate limiting
  • 100+ bits — appropriate for anything protecting data at rest: a password manager's master key, a disk, a backup archive

The gap matters because online and offline attacks are not comparable. An online login might allow ten attempts a minute. An attacker holding a stolen password hash runs billions per second on a GPU.

Why passphrases work

Four random words from a 256-word list gives 32 bits. That sounds low next to a 20-character random string — but a passphrase you can actually type on a phone keyboard and remember beats a strong password you write on a sticky note.

The strength comes entirely from the randomness of the selection, not from the words themselves. Picking four words yourself produces something far weaker than it looks, because human choices cluster hard around common, related, memorable words.

Let the generator choose. That is the whole point.

Frequently asked questions

How many bits of entropy are enough?
Around 75 bits is comfortable for an online account with rate limiting. For anything protecting data at rest — a password manager's master key, a disk — aim for 100 or more.
Are passphrases really as strong?
Yes, given enough words. Four random words from a large list beats a short mangled password, and is far easier to type. Strength comes from the randomness of the selection, not from substituting 3 for e.
Could someone else see the passwords I generate?
No. They are produced by crypto.getRandomValues() inside your browser and never transmitted, logged or stored. Reloading the page discards them permanently.