nicetool.dev logo

Password Generator

Choose the length and character types. Passwords are generated in your browser with crypto.getRandomValues.

How many
    Very strong130 bits of entropyBrute force: longer than the age of the universe

    Check a password

    The estimate assumes random characters. Real words, names and keyboard patterns are much weaker than the number suggests. The password never leaves this page.

    What makes a password strong?

    Password strength comes from length and randomness. Each extra character multiplies the number of guesses an attacker needs, so a random 16-character password with letters, numbers and symbols has about 100 bits of entropy and is far beyond brute force. This generator uses the browser Web Crypto API (crypto.getRandomValues) with unbiased sampling, which is suitable for security-sensitive use, unlike Math.random.

    Features

    • • Cryptographically secure randomness with no modulo bias
    • • Length from 4 to 128, up to 20 passwords at once
    • • Every selected character type is guaranteed to appear
    • • Exclude look-alike or custom characters
    • • Entropy, strength and brute-force time estimate, plus a checker for existing passwords

    Generated locally

    Passwords are created in your browser and are never sent, logged or stored anywhere. You can disconnect from the internet after the page loads and the generator keeps working.

    Web Crypto API, 100% client-side.

    How to use the Password Generator

    1. 1

      Set the length with the slider or the number box. 16 characters or more is a good default for accounts you store in a password manager.

    2. 2

      Choose the character types. If a site rejects some symbols, add them to "Exclude characters" instead of turning symbols off completely.

    3. 3

      Turn on "Exclude look-alike characters" when the password will be read aloud or typed from paper, so I, l, 1, O and 0 cannot be confused.

    4. 4

      Pick how many passwords you want, copy one, and save it in your password manager right away. Use the checker below to estimate the strength of an existing password.

    Practical examples

    New online accounts

    Generate a unique 20-character password for every site. If one service is breached, attackers cannot reuse that password elsewhere (credential stuffing).

    Wi-Fi networks

    A random 16 to 20 character WPA2/WPA3 key without look-alike characters is strong and still possible to type on a TV or game console.

    Database and service credentials

    Create long passwords for database users, SMTP accounts or admin panels, and store them in a secrets manager or .env file rather than in code.

    Team onboarding

    Generate a temporary password for a new colleague and require a change at first login, instead of reusing a default like Welcome123.

    Frequently asked questions

    How long should my password be?+

    For accounts protected by a password manager, 16 to 20 random characters is plenty. Length adds more strength than complexity: each extra character multiplies the number of possible passwords.

    Is a passphrase better than a random password?+

    A passphrase of five or more random words is strong and easier to remember, so it suits a master password. For everything stored in a manager, random characters are shorter for the same strength.

    How is the crack time estimated?+

    It assumes an offline attack at 10 billion guesses per second against a fast hash and a password made of random characters. Real-world passwords containing words or patterns fall much faster than the estimate.

    Can this site see my password?+

    No. Passwords are generated with crypto.getRandomValues in your browser and never sent, logged or stored. The checker also runs locally.