Skip to main content
ToolsBay

Runs in your browser — nothing is uploaded · verify

Secure Password Generator — free, and it runs in your browser

Generate strong passwords locally with a live strength estimate.

  • Values come from the Web Crypto API rather than Math.random, so they are unguessable.
  • Set the length and character classes to satisfy whatever the site demands.
  • The password is generated in your browser and never transmitted or logged.

—

Generated with your browser's cryptographic random number generator. Nothing is sent over the network, and the password is guaranteed to include at least one character from every set you enable.

  • 70 tools

    Free, with no account and no watermark

  • 0 bytes

    Of your files or text uploaded — this tool runs in the tab

  • No queue

    The work happens in this tab, not in a line behind other users

Three steps, nothing to install

Secure Password Generator in three steps

  1. Set it up the way you need it

    Set the rules

    Length, and which character classes to include. Enough to satisfy the sites that impose their own odd requirements.

  2. GenerateFresh values on every press

    Generate and check the strength

    A fresh password appears on every press, with an estimate of how much work it would take to guess.

  3. Copy PASSWORD

    Copy it to your manager

    Straight from the page into your password manager, without a round trip through anything else.

Why use Secure Password Generator

  • Real randomness, not Math.random

    Values come from the Web Crypto API. Math.random is seeded predictably and is unfit for anything protecting an account — this tool used to use it, and that was a real bug.

  • Generated where you are

    A password generated on a server has been transmitted before you ever see it. This one is produced in your tab and goes nowhere else.

  • Free, with nothing to sign up for

    No account, no watermark, no daily cap and no trial that expires. Every tool on this site behaves the same way.

Frequently asked questions

No. It is generated in your browser and never transmitted, logged or stored. Reloading the page discards it. You can confirm this by opening your browser devtools network tab — no request carries the password.

Why the random source matters

The critical part of a password generator is invisible: where the randomness comes from. A generator built on Math.random() produces output that looks random and is not. That function is a deterministic algorithm seeded from a small amount of state, and given a handful of outputs an attacker can reconstruct the generator and predict every password it will ever produce.

This tool uses crypto.getRandomValues(), which draws from the operating system's entropy pool — the same source used for TLS keys. It also uses rejection sampling rather than a modulo, because random % 26 makes the first few letters of the alphabet measurably more likely than the last few.

Reading the entropy number

Entropy in bits is a measure of the search space. Each additional bit doubles the work an attacker must do. A 12-character password using all four character sets is about 79 bits; 20 characters is about 131 bits. Below roughly 60 bits, a well-resourced attacker with stolen password hashes can brute-force offline. Above about 100 bits, the attack is not feasible with any foreseeable hardware.

What actually protects an account

A strong unique password only helps if it is unique. Reuse is what turns one breached site into a dozen compromised accounts, which is the argument for a password manager: it makes generating a different long random password per site the path of least effort. Enable two-factor authentication wherever it is offered — it protects you even if the password does leak.

For random identifiers rather than passwords, see the UUID generator. To produce a one-way digest of a value, see the hash generator.

Related guides

More tools

70 tools, none of which want your file

Everything this tool does happens in the page you are looking at. No account, no upload, no watermark.