About
Set a length, choose which character groups to include, and take the result straight to your password manager. Generation uses the browser's cryptographic random source rather than the ordinary one, and the password exists only in the page in front of you.
How to use
Move the length up to what the site will accept, tick the character groups you need, generate, and copy. Paste it into your manager before you close the tab, because nothing here remembers it.
Length does more work than symbols
Every extra character multiplies the search space, while adding one symbol to a short password barely moves it. A twenty character password drawn from letters and digits is harder to attack than a ten character one bristling with punctuation. Symbol requirements persist because policies were written that way, not because they are where the strength comes from. Set length first and treat character groups as compliance.
Matching what the site will actually accept
Password fields quietly reject things: a maximum length nobody documents, a ban on spaces, a rejection of quotes because of what they do to a query. When a generated password fails, do not conclude the tool is broken. Turn off the group that is most likely at fault, add a few characters, and try again. Keeping a note of a site's quirks in the manager entry saves the next rotation.
Where the randomness comes from
The browser exposes two random sources. The ordinary one is fast, predictable enough to be reproduced, and fine for shuffling a list. The cryptographic one is the one to use for anything that guards an account, and it is what this page calls. That difference matters more than the character set: a predictable generator with symbols is worse than a good generator without.
FAQ
How long should it be?
Sixteen characters is a sensible floor for an ordinary account and costs you nothing when a manager is doing the typing. Push higher for anything that protects other credentials.
Can I get the same password back if I lose it?
No. Each press produces a fresh value and there is no history. Save it before you navigate away.
Is the result sent to a server?
It is not. The value is produced by the browser and stays in the tab.
The site rejects my password. What now?
Turn off the symbol group and generate again, then add length to make up for it. Sites that ban symbols are common and length is the cheaper thing to increase.
Related tools
- Security and generator tools
- Password Strength Checker
Estimate strength locally, nothing leaves the tab.
- SHA Hash Generator
SHA-1, SHA-256 and SHA-512 digests, computed locally.
- Random String Generator
Random tokens and test data, generated locally.
- Online 2FA Code Generator
Turn a Base32 secret into a 6 digit TOTP code.