FreeMicroTools

Password Generator

Strong random passwords and memorable passphrases, made on your own device.

Made on your device with your browser's secure random generator. Never sent or stored.

Kind of password

Make several at once

Password Generator at a glance

Price
Free
Sent or stored
Never, it runs in your browser
Randomness
Browser's secure random generator
Length
6 to 64 characters, or 3 to 10 words
Batch
Up to 25 at once
Sign-up
Not needed

Generate a strong random password with the length and characters you choose, or a memorable passphrase of random words that is easier to type and remember. See how strong it is and how long it would take to crack, copy it in one click, or make a batch at once. Passwords are created by your browser's secure random generator and are never sent or stored.

What makes a password strong

A password is strong when there are too many possibilities for a computer to try them all. Two things decide that: how long it is, and how many different characters each position could be. Length wins. Each extra character multiplies the number of possibilities, while adding symbols only enlarges the alphabet a little. A 20-character password made only of letters is far harder to crack than an 8-character one full of symbols.

The other half is that it must be random. People choosing their own "random" passwords follow patterns attackers know well: a capital at the start, a number and an exclamation mark at the end, a name or a year in the middle. This generator uses your browser's cryptographically secure random number generator, the same source browsers use for encryption, and picks every character with equal chance.

Random characters or a passphrase?

  • Random characters pack the most strength into the fewest characters. They are ideal when a password manager fills them in for you.
  • A passphrase of five or more random words, like Cedar-Otter-Lantern-Quartz-Meadow, is very strong and much easier to remember and type. It suits the few passwords you must type by hand: your computer login, your password manager and your email.

Reading the strength meter

The meter shows the password's strength in bits: every extra bit doubles the number of guesses needed. The time to crack assumes a serious offline attack making 10 billion guesses a second against a stolen database. Aim for Strong (64 bits or more) for important accounts, and Very strong (80 bits or more) for anything that protects other passwords.

Good habits

  • Use a different password for every account.
  • Store them in a password manager rather than a document or notebook.
  • Turn on two-step verification wherever it is offered. It protects you even if a password leaks.

What it does

  • Random passwords from 6 to 64 characters
  • Choose uppercase, lowercase, numbers and symbols, with at least one of each included
  • Leave out look-alike characters such as l, 1, I, O and 0
  • Memorable passphrases of 3 to 10 random words
  • Strength meter with an estimated time to crack
  • Make 5, 10 or 25 at once
  • Uses your browser's cryptographically secure random generator, and nothing is sent or stored

Questions

Are the passwords sent anywhere or saved?

No. Each password is created by your browser on your own device using its secure random number generator. It is never sent to us, never saved, and gone when you close the tab.

How long should a password be?

At least 12 characters for everyday accounts, and 16 or more for email, banking and password managers. Length adds more strength than symbols do.

What is a passphrase, and is it as safe?

A passphrase is several random words, like Maple-River-Kettle-Orbit-Lemon. Five or more truly random words are very hard to crack and much easier to remember and type than random characters. The words must be chosen randomly, not by you.

How is the time to crack worked out?

It assumes an attacker who has stolen a password database and can try 10 billion guesses a second, which is a fast, well-equipped attack. It is shown to compare passwords, not as a guarantee.

Why leave out look-alike characters?

Characters like l, 1 and I, or O and 0, are easy to mix up when reading a password aloud or typing it from paper. Leaving them out makes each character slightly less random but the password much easier to use.

Some sites reject symbols. What should I do?

Turn off symbols and make the password a few characters longer instead. A 20-character password of letters and numbers is stronger than a 12-character one with symbols.

Should I reuse a strong password?

No. Use a different password for every account, so one leak cannot unlock the others. A password manager remembers them for you.

More

Privacy policy · Support · Changelog