Yes. This tool uses window.crypto.getRandomValues() — the Web Crypto API — which draws from the OS's cryptographically secure random source. It does not use Math.random(), which is predictable and unsuitable for security purposes.
Generate cryptographically secure passwords using your browser's built-in Web Crypto API — configurable length, character sets, quantity, and an entropy-based strength meter. Nothing is sent to any server.
Math.random(), which is a pseudo-random
number generator — fast, but not cryptographically secure, meaning an attacker who observes
enough output could potentially predict future values. This tool uses
window.crypto.getRandomValues(), the Web Crypto API built into every modern
browser, which draws from the operating system's cryptographically secure random source —
the same randomness used by TLS and key generation. Nothing is sent to any server.
Choose length, character sets, and how many passwords to generate.
Click Generate — all passwords are created using Web Crypto API randomness.
The entropy meter shows how many bits of randomness each password has.
Copy individual passwords or download the full list as a .txt file.
Password strength isn't about complexity rules — it's about entropy (bits of randomness). A 16-character random password using all four character sets has ~104 bits of entropy, making it effectively uncrackable by brute force at any realistic computing scale. The table below shows what different entropy levels mean in practice.
| Entropy | Strength | Time to crack |
|---|---|---|
| < 28 bits | Very Weak | Instant |
| 28–35 bits | Weak | Minutes |
| 36–59 bits | Fair | Hours–months |
| 60–127 bits | Strong | Centuries |
| 128+ bits | Very Strong | Effectively infinite |
A strong, unique password is only useful if you can actually use it — which means you need a password manager. Never reuse passwords across sites. One breach exposes every account that shares the same password (credential stuffing).
Yes. This tool uses window.crypto.getRandomValues() — the Web Crypto API — which draws from the OS's cryptographically secure random source. It does not use Math.random(), which is predictable and unsuitable for security purposes.
No. Generation happens entirely in your browser. Nothing is transmitted to any server at any point.
Minimum 16 characters for any online account. For server passwords and API keys, 24+ characters. If using a password manager and never typing it manually, 32+ costs nothing and adds significant security margin.
Entropy measures unpredictability in bits. A 16-character password from a 94-character pool has ~104 bits of entropy — requiring 2^103 guesses on average to crack, which is effectively impossible with any current computing technology.