Strong passwords, made in your browser
Generate a random password, a passphrase of real words or a PIN in one click. Choose the length, the kinds of characters, leave out look-alikes or the symbols a site refuses, and see how strong the result is and how long it would take to crack. Need many? Generate up to 50 at once and copy them or download them as a text file. No account, no sign-up: the passwords are made on your device and never leave it.
How to generate a password
- Choose a password, a passphrase or a PIN.
- Set the length and the characters: a new one is made at each change.
- Copy it, or click Regenerate for another one, then save it in your password manager.
What to use it for
- New accounts: a different random password for every site, so one leak does not open the others.
- A master password: a passphrase of 6 words for your password manager or your computer.
- Wi-Fi: a long password without look-alike characters, easy to read from a label.
- Teams and IT: a batch of temporary passwords for new accounts, downloaded as a text file.
- PIN codes: a random code for a phone, a door or a safe, instead of a birthday.
What makes a password strong
Randomness and length. Passwords people invent follow patterns (a word, a capital at the start, a year and an exclamation mark at the end) that cracking tools try first. A random password has no pattern: the only way is to try every possibility. The passphrases use the word list of the Electronic Frontier Foundation (CC BY 3.0): 7,776 common words, chosen to be easy to type and hard to confuse.
Frequently asked questions
Is it safe to generate a password online?
Here, yes: the passwords are made by your own browser, with its cryptographic random generator (the one used for encryption), not on our server. Nothing you generate is sent, saved, logged or put in the page address. You can even disconnect from the internet once the page is open: it keeps working.
How long should a password be?
At least 16 characters for important accounts (email, bank, password manager), and 12 at the very least elsewhere. Length matters more than symbols: each extra character multiplies the number of possibilities, while a symbol only widens the choice for one position.
Password or passphrase: which is better?
A random passphrase of 6 words (77 bits) is about as strong as a random password of 12 to 13 characters with symbols, and much easier to type on a phone and to remember. Use passphrases for what you type by hand (your computer, your password manager), and long random passwords for everything a password manager fills in for you.
What does the strength mean?
It is the entropy in bits: the number of guesses an attacker would need if they knew exactly how the password was made (2 to the power of the bits). The time to crack assumes an offline attack at 100 billion guesses per second, the worst realistic case, so a real attack is usually much slower. Below 56 bits is weak, 72 and above is strong.
What are look-alike characters?
Characters that are easy to confuse when you read or type them: zero and the letter O, one, lowercase L and uppercase i. Leave them out when a password will be read on screen or on paper, for example a Wi-Fi password. It makes the password a little weaker, so add a character or two.
A site rejects my password. What can I do?
Some sites limit the length or the symbols they accept. Lower the length, type the refused symbols in "Leave out these characters", or turn symbols off and make the password longer instead. Every kind of character you keep on is used at least once, as most sites require.
Related tools
- QR code generator: share your new Wi-Fi password as a QR code.
- Base64: encode and decode text in Base64.