Cryptographic randomness
Every character comes from crypto.getRandomValues(), your browser's cryptographically secure random number generator, not Math.random().
Create strong, random, secure passwords right in your browser. Pick the length and characters, see the strength in bits, and copy with one click. No account, no download, and nothing stored or sent anywhere.
Last updated
A password is only as strong as the randomness behind it. Here's what this generator does differently from a quick script or a person picking characters.
Every character comes from crypto.getRandomValues(), your browser's cryptographically secure random number generator, not Math.random().
Rejection sampling gives every character in the pool exactly the same chance, so no letter or symbol shows up more often than it should.
The password is built by code running in this page. It isn't sent to a server, logged, or saved, and the generator keeps working even if you go offline.
Strength is measured in bits of entropy: length × log2(number of possible characters). Every extra bit doubles the number of guesses an attacker needs. Length matters most: each added character from the full set adds about 6.5 bits.
| Characters used | Length | Entropy (bits) | Meter rating |
|---|---|---|---|
| Lowercase only | 16 | 75.2 | Good |
| Letters and numbers | 8 | 47.6 | Fair |
| Letters and numbers | 12 | 71.5 | Good |
| Letters and numbers | 16 | 95.3 | Strong |
| All four types | 12 | 77.5 | Good |
| All four types | 15 | 96.9 | Strong |
| All four types (default) | 16 | 103.4 | Excellent |
| All four types | 20 | 129.2 | Excellent |
| All four types | 24 | 155.0 | Excellent |
Entropy for passwords made by this generator. All four types = 88 characters (A–Z, a–z, 0–9, and 26 symbols). These figures apply only to randomly generated passwords. Passwords people make up are far weaker than their length suggests.
The National Institute of Standards and Technology's Digital Identity Guidelines, NIST SP 800-63B-4 (final, August 2025), changed a lot of the old advice. The short version for anyone choosing a password:
In practice, a 16-to-20-character random password from this page, saved in a password manager, meets or beats every one of those points.
Yes. Passwords are created in your browser with the Web Crypto API (crypto.getRandomValues), the same cryptographically secure random source browsers use for encryption keys. They are never sent to a server, logged, or saved.
No. The page has no server-side code for the generator, no accounts, and no cookies. Each password exists only on your screen until you copy it or generate a new one.
Use at least 15 characters for any password that is your only sign-in factor. That's the minimum in NIST SP 800-63B-4. The default here is 16 characters with all character types, about 103 bits of entropy. For accounts that matter most, such as email, banking, and your password manager, 20 or more is better.
Symbols add strength per character, but length adds more. If a site rejects some symbols, choose “Just - _” or turn symbols off and add four or five characters to make up the difference.
It removes characters that are easy to confuse when you read or type them: lowercase l, uppercase I, the number 1, uppercase O, and zero. Use it when you'll type the password by hand, like on a TV or printer. It lowers strength only slightly; 16 characters still comes out around 102 bits.
Yes. Once the page has loaded, generating passwords needs no internet connection, because everything runs in your browser.
Yes. No sign-up, no ads, no limits. It's a free tool from Veteran Solutions, LLC, a service-disabled veteran-owned small business in Waco, Texas.
Use a password manager, with a different random password for every account. Turn on multi-factor authentication or passkeys wherever they're offered, so a stolen password alone isn't enough to sign in.
Monitoring assessments, NOC runbooks, network administration, and hands-on hardware deployment from a service-disabled veteran-owned small business in Waco, Texas.