Random password generator
Choose the length and the kinds of characters. The password is made by your browser and shown to you only.
This tool needs JavaScript. The rest of the page works without it.
Your result will appear here.
Something went wrong. Your entries are still here.
What this tool does
It makes a password of random characters with the length you set, from 4 to 128. You choose which kinds of characters are used: lowercase letters, uppercase letters, digits and the 13 symbols ! @ # $ % ^ & * - _ = + ?
The password contains at least one character of every kind you ticked. It is not sent to this site, not stored in your browser and gone when you leave the page.
How to use it
- Set the length. 16 is preset; use more where the service allows it.
- Untick the kinds of characters that the service does not accept.
- Tick “Leave out look-alike characters” if you will have to read or type the password by hand.
- Select “Generate password” and then “Copy result”, and paste the password into your password manager and into the service.
How the password is made
All characters of the ticked kinds form one pool. For every place of the password, the tool draws one character from the pool with the cryptographic generator of your browser. Values that would favour some characters are thrown away and drawn again.
If the finished password lacks one of the ticked kinds, the whole password is thrown away and a new one is made. The tool does not repair single places, because that would make some passwords more likely than others.
The strength is given in bits of entropy. It is the number of characters multiplied by the base-2 logarithm of the size of the pool, less a small amount for the passwords that were excluded because they lack a kind. Each additional bit doubles the number of guesses that an attacker needs on average.
Worked example
With all four kinds the pool has 26 + 26 + 10 + 13 = 75 characters. A password of 16 characters has 16 × 6.23 = 99.7 bits before and 99.4 bits after the small deduction. The tool rounds down and shows 99.
| Length | Kinds of characters | Pool | Entropy |
|---|---|---|---|
| 8 | all four | 75 | about 48 bits |
| 12 | letters and digits | 62 | about 71 bits |
| 16 | all four | 75 | about 99 bits |
| 20 | all four, no look-alikes | 69 | about 122 bits |
The table shows that length counts for more than symbols: four more characters add more strength than any additional kind of character.
Using the password safely
- Use every password for one account only.
- Keep passwords in a password manager. Random passwords are not meant to be remembered.
- The guideline of the US standards institute NIST asks services to require at least 15 characters where a password is the only protection, to accept at least 64, and not to demand particular mixtures of characters.
- Copying puts the password on the clipboard of your device, where it usually stays until you copy something else. Copy another text afterwards on a shared device.
- Switch on a second factor where the service offers it. A strong password does not help if it is typed into a fake page.
Common mistakes
- Making the password shorter so that it is easier to type. Keep the length and leave out the look-alike characters instead.
- Changing a generated password by hand into something memorable. That removes the randomness that makes it strong.
- Sending the password by email or chat.
- Using a short password because it contains symbols. Eight characters with symbols are far weaker than sixteen letters.
Frequently asked questions
- Is it safe to create a password on a website?
- This tool makes the password in your browser and transmits nothing, which an automatic test of the site checks. You still have to trust the page, as with any program. If you have a password manager, its built-in generator is the more convenient choice, because it also stores the password.
- Do you store the passwords?
- No. The password is not sent to this site and not written to the storage of your browser. It disappears when you create another one or leave the page.
- How long should a password be?
- As long as the service allows without trouble. 16 random characters are a strong choice for most accounts. The NIST guideline names 15 characters as the least for accounts that are protected by the password alone.
- Which characters are left out as look-alikes?
- The capital letters O and I, the lowercase letters o and l, and the digits 0 and 1. The pool then has 69 instead of 75 characters, which costs about 2 bits at 16 characters.
- A service rejects the password. What can I do?
- Some services accept only certain symbols. Untick the symbols and add two or three characters to the length to make up for the smaller pool.
- Can the tool make a passphrase of words?
- Not this page: it makes passwords of single characters. The passphrase generator on this site draws words from the published EFF word list and shows how strong the result is.
Last updated: September 29, 2026