Generate strong random passwords free. Choose length and character types — created securely on your device, never sent anywhere.
The 10-second test: switch off your Wi-Fi (or turn on airplane mode) and use this tool anyway. It keeps working — because there is no server doing the work.
The technical check: open your browser's developer tools, go to the Network tab, and run the tool. Your file is never sent anywhere.
Measured live on this page — files transmitted: 0 · file data sent: 0 bytes
This counter hooks the browser's own networking functions, so it would rise the instant any file data left this page. The only thing this site ever transmits is the contact form, if you choose to send one.
Select files
or drag & drop — pasting works too (Ctrl+V)
Working…
Processed on your device — 0 bytes uploaded
Thanks — feedback received!
Pick a length, choose which character types to include, and copy your password. Every password is generated with your browser's cryptographic randomness, entirely on your device — we never see it, store it or send it anywhere.
Tip: 16+ characters with all four character types is effectively uncrackable. Store it in a password manager rather than reusing it.
The instinct is to add symbols and numbers. The mathematics says length matters far more. Each extra character multiplies the number of possibilities, so a long passphrase of ordinary words is stronger than a short string of punctuation — and you can actually remember it. If a site allows it, favour length.
Using your browser's cryptographic random number generator, the same facility used for real security work — not the ordinary random function, which is predictable if you know its state. Every password is created on your device and never transmitted. Nothing is logged, because there is no server to log it.
Never reuse one. Breaches are constant, and attackers take the email and password from one leak and try them everywhere else. That is how most accounts are actually compromised — not by anyone cracking a strong password, but by reusing a weak one. A unique password per site is the single highest-value habit, which in practice means using a password manager.
A password manager is the correct answer. If you are not going to use one, a notebook kept physically safe is genuinely better than reusing the same password everywhere — the realistic threat is a remote attacker with a leaked password list, not a burglar reading your notes.
This one, yes — the password is generated on your device using your browser's secure random number generator. Nothing is transmitted; you can even load the page and turn off your internet first.
At least 16 characters for important accounts. Length beats complexity — every extra character multiplies the cracking time.
Easily-confused characters (like l, 1, O and 0) are excluded so passwords are easier to read and type correctly.
Yes. Length adds far more strength than symbols do, and a long passphrase is easier to remember than a short jumble.
They are produced by your browser cryptographic random generator, on your device. Nothing is sent anywhere and nothing is stored.
Never reuse one. Most account compromises come from credentials leaked in one breach being tried everywhere else.
Thanks — we read everything and reply when it matters.