How to use the password generator
Pick a mode — Random password for maximum strength on sites that accept them, or Memorable passphrase when you need to type it by hand or remember it. Adjust the options, click Generate. Click the output box to copy, or press Copy. The password is hidden until you click — protecting against shoulder-surfing.
Entropy — why we show real numbers
A word like "Strong" doesn't tell you much. This tool shows actual entropy in bits — a measure of how many guesses an attacker would need. Each extra bit of entropy doubles the search space. A 20-character random password from the full character set has around 130 bits, which is comfortably beyond any practical attack.
Crack-time estimate
The crack time shown assumes an offline attack against a stolen database using high-end GPUs at roughly 10 billion guesses per second. Online attacks — where a site locks out after a few attempts — take vastly longer, but this pessimistic number tells you the true worst case.
Random password vs passphrase
Both approaches are strong if the entropy is high enough. The trade-off:
- Random password — shorter, more entropy per character, but impossible to remember. Best for accounts stored in a password manager.
- Passphrase — longer, easier to memorise and type.
correct-horse-battery-staplehas about 77 bits of entropy and would take centuries to crack. Best for master passwords and anything you need to type manually.
Presets explained
- PIN (numbers) — 6-digit numeric code for locks and phones.
- WiFi — 20 characters, no symbols (some routers reject them), mixed case and digits.
- Banking — 16 characters, all character types, look-alikes excluded so you don't mis-type on a phone.
- API key — 40 characters, alphanumeric only (URL-safe), for use in code and config files.
- Maximum — 64 characters, full character set. For password managers and encrypted disk images.
Clipboard auto-clear
When you copy a password, it lives in your clipboard until you copy something else — sometimes for hours. This tool automatically clears the clipboard 30 seconds after you copy. You'll see a small countdown at the bottom of the page. Click Cancel to keep it longer.
Why use this tool?
Unlike online password generators that send your password to a server (hoping it's discarded), this one never transmits anything. It uses your browser's built-in crypto.getRandomValues() — the same source of randomness used by operating systems for encryption keys. The page works offline after the first visit.
Common questions
Is this password generator safe?
Yes. Passwords are generated locally using the browser's cryptographic random number generator. Nothing is sent over the network.
How long should my password be?
Sixteen characters or more with mixed case, numbers and symbols is a strong default. For high-value accounts, use 24 or more.
Should I use symbols?
Yes, when the site allows them. Symbols add entropy. If a site rejects them, the length compensation is fine — 24+ characters with mixed case and numbers is still very strong.
What is a passphrase and is it safer?
A passphrase is a sequence of random words such as correct-horse-battery-staple. Because words are memorable, you can make them long — and length matters more than character variety for resisting brute-force attacks.
What does entropy mean?
Entropy in bits measures how unpredictable a password is. Each additional bit doubles the number of possible passwords, so more bits means exponentially more effort to crack.
Why is the password hidden by default?
To prevent shoulder-surfing. If someone is looking at your screen, they can't see the password until you click to reveal it. Once you click Show, the password stays visible across subsequent generations until you click Hide.
Does the clipboard clear work on all browsers?
The auto-clear uses the modern Clipboard API. It works in Chrome, Edge, Firefox, Safari and most mobile browsers. If it's unavailable, the timer won't appear and the password stays in your clipboard.
Is it safe to use the same password everywhere?
No. A single leaked password compromises every account that shares it. Use a password manager to give every site a unique password — you only need to remember one master passphrase.