Free tool · Runs in your browser

Free random
password generator.

Create strong, random, secure passwords right in your browser. Pick the length and characters, see the strength in bits, and copy with one click. No account, no download, and nothing stored or sent anywhere.

generating…
—

Length 16 characters
l 1 I O 0
Every password is generated locally, right in your browser, using its built-in cryptographic random generator. Nothing you generate here is ever stored, logged, or transmitted — not to Veteran Solutions, not to anyone.

Last updated

How it works

Truly random, and it never leaves your device.

A password is only as strong as the randomness behind it. Here's what this generator does differently from a quick script or a person picking characters.

01

Cryptographic randomness

Every character comes from crypto.getRandomValues(), your browser's cryptographically secure random number generator, not Math.random().

02

No modulo bias

Rejection sampling gives every character in the pool exactly the same chance, so no letter or symbol shows up more often than it should.

03

Local only

The password is built by code running in this page. It isn't sent to a server, logged, or saved, and the generator keeps working even if you go offline.

Password strength

How strong is a random password?

Strength is measured in bits of entropy: length × log2(number of possible characters). Every extra bit doubles the number of guesses an attacker needs. Length matters most: each added character from the full set adds about 6.5 bits.

Characters usedLengthEntropy (bits)Meter rating
Lowercase only1675.2Good
Letters and numbers847.6Fair
Letters and numbers1271.5Good
Letters and numbers1695.3Strong
All four types1277.5Good
All four types1596.9Strong
All four types (default)16103.4Excellent
All four types20129.2Excellent
All four types24155.0Excellent

Entropy for passwords made by this generator. All four types = 88 characters (A–Z, a–z, 0–9, and 26 symbols). These figures apply only to randomly generated passwords. Passwords people make up are far weaker than their length suggests.

Current guidance

What NIST says about passwords now.

The National Institute of Standards and Technology's Digital Identity Guidelines, NIST SP 800-63B-4 (final, August 2025), changed a lot of the old advice. The short version for anyone choosing a password:

  • Length wins. At least 15 characters when a password is the only thing protecting an account, and at least 8 when it's paired with multi-factor authentication.
  • Long passwords should be allowed. Sites should accept at least 64 characters.
  • No forced complexity rules. Sites shouldn't require a mix of character types.
  • No scheduled resets. Change a password when there's evidence it's been compromised, not every 90 days.
  • Breached passwords get blocked. Sites should check new passwords against lists of known-compromised and common passwords.
  • Password managers are encouraged. Sites should allow autofill and pasting.

In practice, a 16-to-20-character random password from this page, saved in a password manager, meets or beats every one of those points.

Good habits

Tips for using your new password.

  • One password per account. Reusing a password lets one breach unlock everything else.
  • Save it in a password manager instead of a note, spreadsheet, or sticky note.
  • Turn on multi-factor authentication or passkeys for email, banking, and work accounts.
  • Protect your email first. It's the reset key for almost every other account.
  • If a site rejects symbols, switch to "Just - _" or turn symbols off and make it longer.
FAQ

Password generator questions.

Is this password generator safe to use?

Yes. Passwords are created in your browser with the Web Crypto API (crypto.getRandomValues), the same cryptographically secure random source browsers use for encryption keys. They are never sent to a server, logged, or saved.

Do you store or see the passwords I generate?

No. The page has no server-side code for the generator, no accounts, and no cookies. Each password exists only on your screen until you copy it or generate a new one.

How long should my password be?

Use at least 15 characters for any password that is your only sign-in factor. That's the minimum in NIST SP 800-63B-4. The default here is 16 characters with all character types, about 103 bits of entropy. For accounts that matter most, such as email, banking, and your password manager, 20 or more is better.

Should I include symbols?

Symbols add strength per character, but length adds more. If a site rejects some symbols, choose “Just - _” or turn symbols off and add four or five characters to make up the difference.

What does “exclude ambiguous characters” do?

It removes characters that are easy to confuse when you read or type them: lowercase l, uppercase I, the number 1, uppercase O, and zero. Use it when you'll type the password by hand, like on a TV or printer. It lowers strength only slightly; 16 characters still comes out around 102 bits.

Does it work offline?

Yes. Once the page has loaded, generating passwords needs no internet connection, because everything runs in your browser.

Is it really free?

Yes. No sign-up, no ads, no limits. It's a free tool from Veteran Solutions, LLC, a service-disabled veteran-owned small business in Waco, Texas.

What's the best way to keep track of random passwords?

Use a password manager, with a different random password for every account. Turn on multi-factor authentication or passkeys wherever they're offered, so a stolen password alone isn't enough to sign in.

Veteran Solutions, LLC

Need help with your network?

Monitoring assessments, NOC runbooks, network administration, and hands-on hardware deployment from a service-disabled veteran-owned small business in Waco, Texas.