Password generator
Generate 1 to 100 random passwords at once. Choose the length, character types and symbols, and exclude look-alike characters. Uses cryptographic randomness in your browser; nothing is saved or sent.
This page does not load analytics or ad scripts.
Passwords are created in this browser and are never saved or sent. They are gone when you close the page.
4 to 128 characters
1 to 100
An estimate from the character pool and length. It assumes a fully random string with no dictionary words or personal details.
Generated passwords
How to use
- Enter the length (4 to 128) and how many passwords you need (1 to 100). The slider changes the length too.
- Choose the character types (uppercase, lowercase, digits, symbols). Use "Symbols to use" to allow only certain symbols, for example when a site accepts a limited set.
- Optionally turn on "Exclude look-alike characters" and "Include at least one of each selected type". The list is regenerated as soon as you change a setting.
- Use "Copy" on a row for one password, or "Copy all" for the whole list, one per line.
Notes and limits
- Passwords are not saved. They are gone when you close the page or generate again, so store the ones you use in a password manager.
- The strength label is an entropy estimate from the number of possible characters and the length. It is not a promise about how long cracking would take.
- With "Include at least one of each selected type", combinations that miss a type are discarded, so the real entropy is slightly lower than shown.
- This page loads no analytics or ad scripts and does not record what you do.
How it works
Randomness comes from the browser's crypto.getRandomValues (a cryptographic random number generator), never Math.random.
Characters are picked with rejection sampling: 32-bit random values from the uneven tail that does not divide evenly by the number of characters are thrown away and drawn again. This avoids the modulo bias of a plain % that makes some characters more likely.
For "at least one of each type", passwords that miss a type are discarded and generated again, so the result is uniform among all passwords that meet the rule.
Entropy is calculated as length × log2(number of possible characters).
FAQ
Are the passwords sent or stored anywhere?
No. They are created only in your browser and are not sent to a server, saved in the browser or recorded by analytics.
How long should a password be?
For most uses, 16 or more characters from all four types (about 100 bits) is a good target. Adjust to what the site allows.
What does "Exclude look-alike characters" do?
It leaves out characters that are easy to confuse in some fonts, such as 0 (zero) and O, or 1, l and I. Useful when a password has to be typed by hand or read aloud.
A site does not accept some symbols.
Type only the symbols that site accepts into "Symbols to use". Clear the box to go back to the default set.
Related guides
- Base64 is not encryption: encoding, encryption and hashing explainedWhat Base64 actually does, why it does not protect secrets, how it differs from encryption and hashing, and how to encode and decode text and files.
Related tools
Last updated: