Password generator with the entropy printed beside every password
Make a random password, a PIN or a word-based passphrase, and see the exact number of bits it carries and the alphabet that number came from. Characters are drawn from crypto.getRandomValues with rejection sampling, so no character is more likely than any other — the flaw that quietly weakens most browser generators. Everything happens in this page: nothing is uploaded, nothing is saved, and no password ever appears in the URL.
- Nothing is uploaded or saved
- Works offline
Ambiguous characters are included. Turn them off only if this password will be read aloud or retyped by hand. Requiring one of each of the 4 selected types narrows what is allowed, so it lowers the entropy shown — the figure on the right accounts for it exactly.
Very weak. 20 × log2(94) = 20 × 6.5546 = 131.1 bits without the “one of each” rule, and 0.0 with it — the rule shrinks the set of allowed passwords, so it costs 131.09 bits rather than adding any. At ten billion guesses a second — a leaked database hashed with something fast — that is instantly on average.
Nothing here is stored. There is no history, no localStorage entry and no URL parameter — reload the page and this value is gone from this tool for good. Paste it into a password manager before you navigate away.
How it works
- 1
Choose what you are actually making
A random password for a password manager, a PIN for a phone or a card, or a passphrase you have to type from memory. They are different jobs with different arithmetic, so they are three modes rather than one slider. The first password appears on its own once the page has loaded — before that there is nothing, because the random source does not exist while the page is being built as static HTML.
- 2
Set the length, then the character types
Length does far more work than variety. Every character you add multiplies the search space by the size of the alphabet, so going from 12 to 16 characters of the full 94-character set adds 26 bits — more than switching on symbols ever will. The toggles are there for sites that demand a digit or refuse punctuation, not because mixing types is what makes a password strong.
- 3
Read the entropy figure, not the colour
Under each password is the alphabet size used, the length, and the result of length × log2(alphabet). Sixteen characters from 94 is 16 × 6.5546 = 104.87 bits, and that is the number printed. If a strength meter anywhere cannot show you the arithmetic behind its verdict, it is asking you to take its word for it.
- 4
Turn on “one of each type” only when a form insists
Requiring at least one character from every selected class shrinks the set of allowed passwords, so it lowers entropy rather than raising it. This page draws again until the rule is met, which keeps the result uniform over the allowed strings and lets it print the exact figure: with the full 94-character set, a 4-character password falls from 26.22 to 22.31 bits. At 16 characters the cost is 0.28 bits and stops mattering.
- 5
Copy it into a password manager, not into a notes app
A password you cannot remember is the point; storing it somewhere that syncs and locks is the other half of the job. Copy puts it on your clipboard and nothing else — this page keeps no history, so once you navigate away or reload, the password you generated is gone from here entirely. That is deliberate, and it means the page cannot show you the last one again.
Frequently asked questions
Where does the randomness come from?
crypto.getRandomValues, which draws on the operating system’s cryptographically strong random source — the same one that backs key generation in your browser. It is not Math.random(). Math.random() is fast, seeded and explicitly not suitable for anything security-related: its internal state can be recovered from a short run of its own output, which means an attacker who sees one password can work out the next. This page has no Math.random() fallback at all. On a browser without a strong source it says so and generates nothing, because output that looks identical and is predictable is worse than no page.
What is modulo bias, and why does it matter here?
It is the most common defect in browser password generators, and it is invisible. The naive way to pick a character is to take a random byte and use alphabet[byte % 94]. A byte holds 256 values, and 256 ÷ 94 is 2 remainder 68 — so the first 68 characters of the alphabet come up three times per 256 bytes and the remaining 26 come up twice. That is 50% more often for two-thirds of the alphabet, on every character, forever. This page uses rejection sampling instead: 94 × 2 = 188, so any byte from 188 to 255 is thrown away and a new one drawn, and the 188 that remain divide evenly. The cost is that about a quarter of draws are discarded. The benefit is that every character really is equally likely.
How long should my password be?
For the full 94-character set, each character is worth log2(94) = 6.5546 bits, so: 8 characters is 52.4 bits, 12 is 78.7, 16 is 104.9 and 20 is 131.1. Anything you keep in a password manager should be 16 or more — you are not typing it, so length is free. Anything you type by hand every day is where a passphrase earns its place. The one number worth remembering is that four extra characters from that alphabet multiply the work by roughly 78 million.
Is a passphrase as strong as a random string?
Per character, no — nowhere close. Per keystroke you will actually get right, often yes. The passphrase mode here draws from a list of exactly 2,048 words, and log2(2048) = 11 bits per word, exactly. Six words is 66 bits. From the 94-character alphabet, ten characters give 65.5 bits and eleven give 72.1 — so a six-word passphrase sits between a ten- and an eleven-character random password, and it is the one of the three you have a chance of remembering. The strength comes only from the number of words and the size of the list — not from the words being unusual, and not from the hyphens between them.
Why is your word list 2,048 words rather than a bigger one?
Because 2,048 is 2 to the power of 11, so each word is worth exactly 11 bits with no rounding and you can check the arithmetic yourself. The list ships inside the page rather than being fetched, which is what lets this page work offline; a downloaded list would make that claim false on first load. The trade-off is stated rather than hidden: the EFF’s well-known list is 7,776 words, worth 12.92 bits each, so a passphrase from it is stronger word for word. Against this list you need one extra word to reach the same strength, and the tool tells you what you have rather than assuming.
Should I exclude ambiguous characters?
Only if a human is going to read the password off a screen and type it somewhere else. The toggle removes capital I, lowercase l, digit 1, capital O and digit 0 — the five characters people misread. That takes the alphabet from 94 to 89, so each character drops from 6.5546 to 6.4757 bits and a 16-character password falls from 104.9 to 103.6 bits. That is a real cost for a real benefit, and it is a bad trade for anything you paste from a password manager.
A site rejects my password because it is too long or has symbols. Now what?
Turn the symbols off and add characters. Losing punctuation takes the alphabet from 94 to 62, which costs 0.6 bits per character — 16 characters of letters and digits is 95.3 bits instead of 104.9. Adding two more characters more than makes it back. A length cap is the harder problem: if you are capped at 12 characters, use all 12, use every class the site allows, and accept that the site has decided how strong your password is allowed to be. It is also a fair signal about how that site stores passwords.
Is a 6-digit PIN safe?
On its own, no — 6 digits is 10^6 = 1,000,000 combinations, or 19.93 bits, which any computer exhausts instantly. What protects a PIN is never the PIN: it is the device wiping or locking after ten wrong attempts. That is why the PIN mode here goes up to 12 digits and why it will tell you the entropy is low no matter what you choose. And it is why a PIN that is a date is worse still: there are only about 37,200 dates in a century, so a birthday PIN cuts the space by 96%.
Does this page keep any of the passwords it makes?
No, in every sense that matters. There is no localStorage, no cookie, no network request, and no password is ever put in the URL — the address bar is a place things get logged, shared and synced without anyone meaning to. The generator runs in JavaScript that was already downloaded with the page, so it keeps working with the network switched off. Reload the page and the password is gone from here permanently; this tool cannot show it to you again, and neither can anyone else.