Password Generator
Cryptographically random, generated on your device, never transmitted. Adjust and copy.
Generated with crypto-grade randomness on your device — never sent anywhere.
Time to crack, roughly
| Password | Modern cracking rig |
|---|---|
| 8 chars, lowercase only | Seconds |
| 8 chars, full character set | Hours to days |
| 12 chars, full set | Centuries |
| 16 chars, full set | Longer than the universe has existed |
The table is the whole argument for the length slider. Every character you add multiplies the work by ~70.
Common questions
What makes a password strong?
Length beats cleverness. A random 16-character password from a full character set would take centuries to brute-force; a "clever" 8-character one with substitutions (P@ssw0rd!) falls in minutes because crackers try those patterns first. Use 16+ random characters, unique per site.
Is it safe to generate a password on a website?
On this one, yes — generation uses your browser's cryptographic random number generator (crypto.getRandomValues) entirely on your device. The password is never transmitted, logged, or known to anyone but you. You can verify: the page works with your internet disconnected.
Why are some characters missing from the output?
Lookalikes are excluded on purpose — l/1/I and O/0 — so passwords survive being read aloud or typed from paper. It costs a negligible amount of randomness and saves real frustration.
How should I store generated passwords?
A password manager (Bitwarden, 1Password, or your browser's built-in one) — that's what makes unique-per-site passwords practical. The one password you memorize is the manager's.