Password Generator
Strong random passwords and passphrases, generated in your browser. Change a setting and you get a new one instantly.
Very weak. Would take less than a second to guess at 10 billion guesses a second.≈ 0 bits
Characters
More optionsRules · several at once · history
Rules
Several at once
Generated in your browser with crypto.getRandomValues; nothing is sent anywhere, and the password is never put in the page address.
Frequently Asked Questions
What makes a password strong?
A strong password typically has at least 12 characters, includes uppercase and lowercase letters, numbers, and symbols. It should avoid dictionary words, personal information, and common patterns. The longer and more random, the better.
Should I use the same password for multiple accounts?
Never use the same password for multiple accounts. If one account is compromised, all accounts with that password become vulnerable. Use our generator to create unique passwords for each account and consider using a password manager.
What are ambiguous characters and why exclude them?
Ambiguous characters are those that look similar and can be confused: 0 (zero) and O (letter O), 1 (one) and l (lowercase L), I (uppercase i). Excluding them prevents typing errors, especially when reading passwords from paper or screens.
What is a passphrase, and is it as strong as a password?
A passphrase is several random words, like "Maple-Otter-Cinema-Frost-Lantern". Each word here is picked at random from a list of 1,287 common words, which adds about 10.3 bits of entropy per word, so five words give about 52 bits. That is comparable to a random 9-character password with every character type, but far easier to type and remember. The strength comes from the words being chosen at random by the generator, not by you.
How does the deterministic password generator work?
The deterministic generator creates a unique password by combining your master password with the website domain (and optionally year/month). It uses SHA-256 hashing so the same inputs always produce the same password. It uses a single fast hash with no salt or key stretching, so it does not slow down guessing: anyone who sees one generated password and knows the method can test candidate master passwords quickly. A weak or common master password can be recovered this way; a long, random one cannot be guessed in practice.
Is the deterministic password generator secure?
Only as secure as your master password. SHA-256 is a sound hash, but here it is the only barrier, and it is fast to compute, so a short or reused master password can be brute-forced from any password it produced. Use a long, unique master password (for example a passphrase of five or more random words) and keep it secret; if someone learns it, they can recreate all of your passwords. For most people a password manager with random passwords is the safer choice.