zerouploads

Password Generator

Make a strong random password or PIN in your browser, with the strength worked out in bits rather than guessed at.

  • Unlimited
  • No signup
  • Private
  • Works offline

Generate a password

What kind of secret

Password129 bits

0 characters · 86-character setnever leaves this page

Strength — very strong

measured, not guessed

character set
86
length
0 characters
entropy
log₂(860) = 129 bits
offline guessing
longer than the universe has existed

Password settings

What it can contain
Rules
crypto.getRandomValues · nothing is sent, stored or remembered

What actually makes a password strong

One number decides it. That number is how many guesses an attacker has to make, which is the size of the alphabet raised to the length. This page shows you that sum instead of a colour.

Length does more work than variety. Twenty lowercase letters are stronger than ten characters with a symbol in them, because every extra character multiplies the work again. A rule that demands one of everything mostly makes passwords people cannot remember or type.

None of it matters if the randomness is weak. Math.random is not built for secrets, and someone who sees a few of its outputs can work out the ones that follow. This page uses crypto.getRandomValues, your browser's cryptographic random source.

Randomness
crypto.getRandomValues, drawn without bias. Never Math.random, which is guessable.
Strength
Entropy in bits, worked out from the alphabet and the length. The page shows the sum.
Rules
Avoid look-alikes, No repeated characters, and One of each kind. Avoiding look-alikes shrinks the alphabet, and the bits figure shows the cost.
Nothing kept
The page makes no request and keeps no log or history. Close the tab and the password is gone for good.

Where to keep it

Keep it in a password manager. A strong password you reuse everywhere becomes useless after one breach, and nobody remembers forty different ones.

The one password worth memorising is the one that unlocks the manager. Make that one long, and never type it into anything but the manager itself.

Frequently asked questions

Is the password sent anywhere?
No. The password is made in this tab and never leaves it. The page sends no request, so there is nothing to log and nothing to leak. Reload the page and it is gone.
How long should a password be?
Sixteen characters or more for anything that matters, and longer for the password that unlocks your manager. Length is the setting that buys the most for the least effort.
What does the bits figure mean?
How many guesses an attacker needs, as a power of two. Sixty bits means about a billion billion guesses. Every extra bit doubles the work, so the jump from 60 to 80 is a million times harder.
Do I need symbols?
Not if the password is long. Symbols add a little to the alphabet and a lot to the trouble of typing it on a phone. A longer password with no symbols usually wins.
Why avoid look-alikes?
Because l, I, 1, O, o and 0 get misread off a screen or a printout. Leaving them out makes a password slightly weaker and much easier to copy by hand. The bits figure drops when you do, so you can see the cost.
Is this random enough to trust?
It uses crypto.getRandomValues, your browser's cryptographic random source, the kind used to make encryption keys. The drawing also throws away values that would favour the first few characters of the alphabet.
Should I write it down?
Use a password manager. If you do write one down, write down the one that unlocks the manager and keep that paper somewhere you would keep cash.
Browse all web tools