Random Password Generator
Create truly random passwords with the exact length and character types you need, generated on your device, never sent anywhere.
How it works
Every character is chosen with your browser's cryptographic random number generator (crypto.getRandomValues), never Math.random, which is predictable.
We use rejection sampling so every character in the pool is exactly equally likely, no “modulo bias” toward some characters.
At least one character from each set you enable is guaranteed, then the result is shuffled. Entropy shows how hard the password is to guess.
Formula
Entropy (bits)
Where:
- length
- = Number of characters
- pool size
- = Distinct characters allowed (e.g. 89 with all four sets)
Worked example
A 16-character password using uppercase, lowercase, numbers and our 27 symbols draws from 89 characters.
16 × log₂(89) ≈ 103.6 bits, well beyond the reach of any brute-force attack.
The Advantage of Total Customization
This tool offers granular control over the output, allowing you to toggle individual character sets to match restrictive web forms. You can even exclude easily confused characters like '0' and 'O', which is essential if you need to read a password aloud or transcribe it. Custom exclusion lists ensure the result is functional for your specific use case, such as generating legacy database passwords that forbid special symbols or require specific starting characters.
By fine-tuning the character pool, you can create passwords that are optimized for human interaction. For example, if you are setting up a temporary access code for a guest, you might choose to exclude symbols entirely to make it easier to type on a mobile device while still maintaining high entropy by increasing the overall string length. This balance between technical rigidity and user experience is the primary strength of a fully manual generator.
Distinguishing Between Generator Types
Understanding the differences is key: the Random Password Generator is for manual control over pools and length. The Strong Password Generator focuses on high-entropy defaults and crack-time estimates. Meanwhile, the Free Password Generator is built for speed, offering simple presets and batches of ten. All use the same secure random generation but cater to different professional workflows, whether you are a developer needs a precise string or a user wanting a quick PIN.
Harnessing Cryptographic Unpredictability
True randomness is the cornerstone of security. This tool leverages the Web Crypto API, drawing entropy from hardware-level noise to ensure every character is independent. This eliminates patterns that dictionary attacks rely on. By increasing pool size and length, you exponentially grow combinations, making the password mathematically impossible to crack in a human lifetime. This is the pure 'random' approach vs. structured passphrases, providing the raw complexity required for modern encryption keys.
Frequently asked questions
It must come from a cryptographically secure source. Ordinary random functions in programming languages can be predicted; the Web Crypto API cannot practically be.