Generate a password
This is for anyone who needs a throwaway-proof password for a new account, a Wi-Fi key or a database user and does not want to invent one by hand. The password is built in this page by JavaScript; it is never sent anywhere, never written to storage, and it disappears when you close or reload the tab. Copy it into your password manager before you navigate away.
Each press produces a different password. The previous one is not kept anywhere, so copy it before generating another.
How it works
The alphabet is four fixed groups, 88 characters in total:
| Group | Characters | Count |
|---|---|---|
| Uppercase | A–Z | 26 |
| Lowercase | a–z | 26 |
| Digits | 0–9 | 10 |
| Symbols | !@#$%^&*()_+-=[]{}|;:,.<>? | 26 |
Nothing outside those 88 characters can appear: no space, quote mark, backslash, slash, tilde or backtick. Those are the characters most often mangled by shell commands, CSV files and configuration formats.
- The length you type must be a whole number from 4 to 30. Anything else — a blank field, 3, 31, 12.5 — produces the message Please enter a whole-number length between 4 and 30. instead of a password.
- One character is drawn from each of the four groups, so every result contains at least one uppercase letter, one lowercase letter, one digit and one symbol.
- The remaining positions are drawn from all 88 characters at once. Repeats are possible and are not avoided.
- The whole string is then shuffled with a Fisher–Yates pass, so the four guaranteed characters are not stuck at the front.
Where the randomness comes from
Every choice uses
crypto.getRandomValues, the browser's
cryptographic random source, filling a 32-bit unsigned integer. It is
not Math.random, which is not designed to be
unpredictable.
Reducing a 32-bit number to a range with a plain remainder would make the first few characters of a group slightly more likely than the last. To avoid that, any draw at or above the largest exact multiple of the range is thrown away and a fresh one is requested. Every character in a group therefore has the same probability.
What a length is worth
With an alphabet of 88, each character adds log2(88) = 6.459 bits of guessing work, so the number of equally likely passwords is 88 raised to the length and the strength in bits is length × 6.459.
| Length | Arithmetic | Bits | Bits after the one-per-group rule |
|---|---|---|---|
| 4 | 4 × 6.459 | 25.8 | 22.0 |
| 8 | 8 × 6.459 | 51.7 | 50.6 |
| 12 | 12 × 6.459 | 77.5 | 77.1 |
| 16 | 16 × 6.459 | 103.4 | 103.1 |
| 20 | 20 × 6.459 | 129.2 | 129.0 |
| 30 | 30 × 6.459 | 193.8 | 193.7 |
The last column exists because guaranteeing one character from each group rules out the results that happen to miss a group, which shrinks the set of possible passwords a little. From 12 characters up the cost is under half a bit — too small to matter. At the 4-character minimum it costs almost 4 bits, because a 4-character result is only ever the four group characters shuffled: 26 × 26 × 10 × 26 × 4! = 4,218,240 possibilities. Four characters is far too short whatever the arithmetic says; the minimum exists for testing, not for real accounts.
Length beats symbol tricks
Adding one more character multiplies the search space by 88. Swapping
an a for an @ in a word you already chose
multiplies it by roughly nothing, because that substitution is one of
the first things a cracking tool tries. The same goes for a capital
at the start and a digit and an exclamation mark at the end: that
shape is so common it is part of every wordlist rule set.
So the useful lever is length, and the reason to use a generator at all is that it does not favour pronounceable or memorable strings the way a person does. No password is unbreakable — given enough time any finite password can be guessed. What a longer random password buys is that the time needed stops being practical.
Storing and reusing
A 20-character random string is not something you will remember, and that is fine. Keep it in a password manager and let the manager fill it; reputable managers encrypt the vault locally with a key derived from one long passphrase, so that passphrase is the one secret you memorise. A browser's built-in manager is a real improvement over a notes file.
The habit that matters most is not reusing a password across sites. When a site is breached, the stolen credentials get replayed against other services, so a password shared between your email and a forum turns one forum's problem into your email's problem.
Turn on multi-factor authentication wherever it is offered, especially on email, because email is usually the reset path for everything else. An authenticator app or a hardware security key is stronger than a code sent by SMS, since a phone number can be taken over by a carrier-level attack. The United States National Institute of Standards and Technology sets out guidance of this kind in Special Publication 800-63B, Digital Identity Guidelines.
Common mistakes
- Generating a password and then shortening it to fit a site's limit. Generate at the length the site accepts instead.
- Editing the result to make it "easier to type". Hand edits concentrate the result into the patterns people pick.
- Leaving the password only on screen. Reloading the page loses it, because nothing is stored.
- Pasting it into a chat, an email draft or a spreadsheet to move it between devices. Use the password manager's sync instead.
- Treating a long password as a reason to skip multi-factor authentication. It protects against a different failure — someone else already having the password.
Limits
- It does not store, sync or remember anything. There is no history and no list of past results.
- It does not check a password against breach databases, and it cannot tell you whether a password you already use was exposed.
- It does not score a password you type in; it only produces new ones.
- It cannot produce passphrases made of words, only random character strings, and the character set cannot be changed.
- Nothing here protects you from phishing or from malware on the device you type the password into. If JavaScript is blocked, the button does nothing; there is no server-side fallback.
Questions
Can the same password be produced twice?
In principle yes, in the same way two dice rolls can match. At 12 characters there are about 1.56 × 1023 possible results, so a repeat is not something you will see.
A site rejected one of the symbols. What now?
The alphabet includes brackets and braces, which some systems still dislike. Generate another password rather than deleting characters from the one you have, so the length stays what you chose.
Is a browser's random source good enough for this?
For generating passwords, yes.
crypto.getRandomValues is specified to be seeded from
the operating system's cryptographic entropy source. A password
manager's own generator is equivalent; the practical advantage of
using the manager is that it saves the password at the same moment
it creates it.
Should I pick 30 characters every time?
Only if you never type it by hand. Past roughly 20 characters the extra bits stop changing any realistic outcome, while the inconvenience of typing on a phone keyboard or a game console keeps growing. The length worth choosing is the longest one you will not be tempted to work around.
Does typing a length send anything to the site?
No. The length is read from the input by JavaScript running in the page and the password is assembled in the same script. There is no network request involved in producing it.
