Choose a length and which character types to include, then generate a random password. Generation uses your browser’s cryptographically secure random number generator — nothing is sent to our server, and nothing generated here is stored anywhere.
Generated locally in your browser using a cryptographically secure random source (crypto.getRandomValues) — nothing is sent to our server, and nothing generated here is stored.
How This Is Generated
Each character is chosen using the Web Crypto API’s crypto.getRandomValues(), a cryptographically secure random source built into your browser — not Math.random(), which is not designed for anything security-sensitive. Selection uses rejection sampling to avoid statistical bias toward any particular character.
The strength estimate shown is a standard entropy calculation (password length × log₂ of the character set size) — a real, commonly used technique, not an arbitrary score. It’s a rough guide to how hard the password would be to guess by brute force, not a guarantee against every kind of attack.
FAQ
Is this password actually secure?
The generation method is cryptographically sound. Actual security also depends on where and how you store and use the password — this tool doesn’t store anything, so once you close the page, the password exists only wherever you’ve saved it yourself.
Why is there no “exclude similar characters” limitation beyond ambiguous ones?
The “exclude ambiguous characters” option removes only the characters most commonly confused when read or typed by hand (l, 1, I, O, 0) — a deliberately small, well-known set, not a broader guess at what might be confusing.