How to use the Password Generator
- Choose a length (16 or more is recommended).
- Pick which character types to include.
- Copy the password into your password manager or sign-up form.
What does this tool do?
Passwords are generated with crypto.getRandomValues, the browser's cryptographically secure random source, using a method with no statistical bias. Each selected character type is guaranteed to appear at least once, which satisfies most site rules.
Length matters more than complexity: a 16-character random password is vastly harder to crack than an 8-character one with symbols.
Why use it?
- Unique passwords for every account.
- Meets typical password rules automatically.
- No accounts, logging or storage.
How strength grows with length
Using all character types (about 88 characters to choose from):
| Length | Entropy | Practical strength |
|---|---|---|
| 8 | ~52 bits | Fair — crackable offline |
| 12 | ~78 bits | Strong |
| 16 | ~103 bits | Very strong |
| 20 | ~129 bits | Beyond brute force |
Privacy
Everything you type is processed in your browser. Nothing you enter is sent to our servers or stored by us. There's no account to create and nothing to install.
Frequently asked questions
Is it safe to do this in a browser?
Yes, because nothing leaves your device. Everything is generated or checked with your browser's built-in cryptography (the Web Crypto API) — no network requests are made with what you type.
How do I remember all these passwords?
You don't need to. Use a password manager (most browsers and phones include one) and remember just one strong master password or passphrase.
Last reviewed by the M2Toolkit team.