Secure Password Generator

Generate cryptographically secure passwords and passphrases with real-time entropy and crack-time estimates. 100% client-side — nothing leaves your browser.

100% Client-side No tracking Web Crypto (CSPRNG) Free forever

Password generator

Strength: – Entropy: – Crack time (offline): –

What Makes a Password Strong?

TL;DR: Password strength comes down to two things — length and true randomness. A 16-character password using all character types reaches approximately 102 bits of entropy, enough to resist modern brute-force attacks for billions of years.

1. Length Is the Biggest Factor

Each additional character multiplies the number of possible passwords by the pool size. Going from 8 to 16 characters (83-character pool) raises entropy from 51 bits to 102 bits — doubling the length doubles the bits, but the actual search space grows exponentially (from 251 to 2102 — a trillion trillion times larger).

2. Cryptographically Secure Randomness

This tool uses window.crypto.getRandomValues(), the browser's cryptographically secure random number generator (CSPRNG). Unlike Math.random(), which is predictable, a CSPRNG produces unpredictable output suitable for security applications.

3. Character Pool Size

More character types mean a larger pool, which means more entropy per character. This tool uses a 21-symbol set (!@#$%^&*()-_=+[]{}<>?), giving a combined pool of 83 characters when all types are enabled.

Entropy Reference

Entropy by length and character pool
Length Character Types Pool Entropy
8Lowercase only2637.6 bits
12Lowercase only2656.4 bits
8Alphanumeric6247.6 bits
12Alphanumeric6271.5 bits
16Alphanumeric6295.3 bits
12All types8376.5 bits
16All types83102.0 bits ✓
20All types83127.5 bits

Crack time assumes an offline attack at 10 billion guesses per second (typical for SHA-256 on a GPU). For bcrypt or Argon2id, actual crack rates are orders of magnitude slower.

Security Standards

NIST SP 800-63B (Digital Identity Guidelines) recommends checking passwords against known-breached lists, allowing passphrases of up to 64 characters, and not enforcing periodic rotation or arbitrary complexity rules. For randomly generated passwords, security professionals broadly recommend targeting 80+ bits of entropy for strong protection.

Privacy guarantee: This generator runs entirely in your browser. No password, no personal data, and no analytics ever leave your device. You can verify this in your browser's developer tools (Network tab shows zero outgoing requests).

Explore the Guides

FAQ

What is the most secure way to generate a password?

Use a generator powered by a CSPRNG (like window.crypto.getRandomValues()), target at least 16 characters across all character types (≈102 bits of entropy), and store it in a password manager. Never invent passwords yourself.

What is password entropy?

Password entropy measures unpredictability in bits. It is calculated as length × log₂(pool size). A 16-character password from an 83-character pool has 102 bits of entropy.

How many bits of entropy should a password have?

Security professionals recommend at least 80 bits for strong protection. Passwords above 100 bits resist brute-force attacks even with high-speed hardware.

Is this generator safe?

Yes. Passwords are generated entirely in your browser using window.crypto.getRandomValues(). Nothing is transmitted to any server.

What is the difference between a password and a passphrase?

A password is a short random string; a passphrase uses multiple random words. Read our full comparison: password vs. passphrase.

What does the crack time estimate mean?

It represents the worst-case time to exhaust all possible passwords at 10 billion guesses per second — a typical offline attack rate against SHA-256 hashes on a modern GPU. Online attacks are far slower due to rate-limiting.

Can I use this tool to create a strong WiFi password?

Yes. WPA2 and WPA3 support passwords from 8 to 63 characters. A 16-character random password gives 102 bits of entropy — far beyond any practical attack. See our WiFi password guide.