Strong Password Generator

Create strong random passwords from a cryptographically secure source directly in your browser, with full control over character types. Nothing you create ever leaves your device.

Press Generate to draw
Advanced Options
Edit the lines above to use custom characters. Each line is treated as a separate character type.

A strong, unique password is the cheapest defense any online account gets — and the moment you need one is rarely convenient: a new Login.gov profile, an IRS online account as the April 15 tax deadline approaches, a new cell phone fresh out of the box, or a long-overdue move to a password manager. This free password generator for the United States creates a random password from a cryptographically secure source in one click. Set Length to the size you need, pick which character classes to include — uppercase and lowercase letters, digits, basic symbols (%$#@!?&), and complex symbols (.,;[]()^-_=+{}:<>|) — and press Generate.

Security is the whole point, so the generator is built on the Web Crypto API (crypto.getRandomValues), which draws its values from the same cryptographically secure system randomness that TLS and other security-critical operations rely on. Unlike generators based on Math.random() or similar predictable pseudo-random functions, it is built so that seeing one result tells an attacker nothing about the next. Generation happens entirely on your device: the password is never sent to a server, never logged, and never seen by us — there is nothing to intercept and nothing for us to store.

The options make it easy to match most sites' password policies. Every password is guaranteed to contain at least one character from each class you selected — so "must include an uppercase letter and a number" is satisfied automatically — and "Ensure approximately equal number of each character type" is on by default, so no single class crowds out the rest. Turn symbols on for maximum strength, or off for legacy systems that reject them. The "No look-alikes" switch removes the characters people misread most often (Il1O0o), and "Exclude cross-alphabet lookalikes" goes further, also removing letters that look identical across the Latin and Cyrillic alphabets.

Need more than one password, or an unusual policy? Set Count to generate a whole list at once — up to 100 passwords, for example when creating accounts for a team — and once Count is above 1, Output format decides how they are separated: Line break, Space-separated or Comma-separated. Everything else lives under Advanced Options. Turn off "Exclude duplicate characters in one password" to allow the same character to appear more than once. If your language has its own alphabet or extra letters, the generator covers 35 of them — from Ukrainian, Greek and Serbian to Polish, Turkish and Vietnamese — so switch on "Local uppercase letters" and "Local lowercase letters" to mix those characters into the result. And for complete control, "Character pools (one per line)" lets you define your own sets: each line becomes a separate character class the generator draws from.

Why choose this password generator?

How is the randomness generated? Your operating system continuously collects entropy — unpredictable noise from hardware events — and feeds it into a cryptographically secure random number generator. When you press Generate, the page's JavaScript requests random values from the browser through crypto.getRandomValues, maps them onto the character classes you selected, checks that every class is represented, and assembles the password. There is no seed to guess, no algorithmic shortcut that specialized password-cracking hardware could replay, and the password never travels over the network — the entire pipeline runs on your device.

Below the result you will see an entropy estimate in bits — a rough guide to password strength: 60+ bits is reasonable for everyday accounts, 80+ is strong, and 100+ is beyond the practical reach of brute force with today's hardware. Two habits matter more than anything else. First, length beats complexity: use 16+ characters for anything important — each extra character multiplies an attacker's work far faster than another symbol class does. Second, uniqueness: when a website suffers a data breach, the leaked login credentials are immediately tried on other services — an attack called credential stuffing — so a single reused password can turn one leak into a full account takeover. Generate a separate password for every account, keep them in a password manager, and enable two-factor authentication wherever it is offered. These recommendations are consistent with guidance from the National Institute of Standards and Technology (NIST). And don't be surprised if a random password contains a short readable fragment or, once duplicates are allowed, a repeated character — random output produces such runs all the time, and they don't make the password any weaker.

FAQ

Is it safe to generate a password online?

With this tool, yes. The password is created entirely in your browser using the Web Crypto API and is never sent to our server or to analytics, so there is nothing for us — or anyone in between — to intercept or store.

How long should my password be?

Use 16 characters or more — the default here — for anything important, from your Login, and never fewer than 15 where the password alone protects an account, the minimum in current NIST guidance.gov sign-in to your checking account. Length beats complexity: each extra character multiplies the number of combinations an attacker must try, which is why the National Institute of Standards and Technology (NIST) favors length over forced composition rules.

Is a random password really better than one I make up myself?

Yes. Human-made passwords follow predictable habits — dictionary words, names, dates, keyboard walks like qwerty123 — and cracking tools try exactly those patterns first. A randomly generated password has no such structure, so an attacker is left with brute force, which a 16-character random password makes practically impossible.

What do the entropy bits under the result mean?

Entropy estimates how unpredictable the password is. Roughly: 60+ bits is reasonable for everyday accounts, 80+ is strong, and 100+ is beyond the practical reach of brute force with current hardware.

What does the "No look-alikes" option do?

It removes characters that are easy to confuse with each other — capital I, lowercase l, digit 1, capital O, digit 0 and lowercase o. Use it when a password needs to be read aloud, printed, or typed from paper.

Can I create fully custom passwords with my own characters?

Yes. Open Advanced Options and use "Character pools (one per line)" to define your own sets. Each line becomes a separate character class, so you can require specific characters from each group — perfect for meeting unusual site requirements.

Can I include letters from my own alphabet?

The local-alphabet feature covers 35 languages — Ukrainian, Greek, Serbian, Polish, Turkish and Vietnamese among them — but English is not one of them, since it uses no extra letters beyond the standard Latin alphabet. If you occasionally need accented characters from another language, add them yourself in "Character pools (one per line)" under Advanced Options, one set per line. Check first that the site accepts such characters — many still allow only Latin letters, digits and common symbols — and remember you may have to type the password on another keyboard; a longer password is the simpler way to add strength.

Why does every password contain a digit and an uppercase letter?

The generator guarantees at least one character from every class you selected, so the result always satisfies typical site requirements like "must contain an uppercase letter and a number". Untick a class to exclude it entirely.

Should I use a passphrase instead of a password?

Passphrases — several random words, as in the diceware method — are great when you have to remember or type a secret, such as the master password of your password manager. For everything that lives inside the manager, a random password of 16 characters or more is as strong as a passphrase of about seven random words, and you never have to type it. Use both: one strong passphrase for the manager, random passwords for everything else.

How often should I change my passwords?

Modern security guidance from the National Institute of Standards and Technology (NIST) no longer recommends changing passwords on a schedule — forced rotation leads to weaker, predictable variations. Change a password when there is a reason to: a breach at the service, a phishing scare, or a shared account. What matters is that every account has its own long, random password.

Do you store or see the passwords I generate?

No. Generation runs locally on your device and the password never leaves your browser, so it never reaches our server and we cannot log or store it. Analytics, if you allow it, records only that the tool was used — never the password.