Password Generator
Create random passwords from 4 to 64 characters with your browser's cryptographic random number generator. Choose the character types and see the estimated strength in bits.
Estimated as length × log2(pool size): 16 characters from a pool of 88.
About the Password Generator
Every character is picked by your browser's cryptographic random number generator (crypto.getRandomValues, part of the Web Crypto API). Random values that would favour some characters over others are thrown away and drawn again, so each character in the pool is exactly as likely as any other. The password is created on your device, shown on the page and never sent anywhere or saved.
When you tick several character types, the generator also makes sure the password contains at least one of each. A new password appears whenever you change a setting, and the refresh icon or Generate New Password gives you another one.
The strength bar shows an estimate in bits, calculated as length × log2(pool size). The default 16 characters drawn from all four types (a pool of 88 characters) comes to about 103 bits; 12 lowercase letters alone come to about 56 bits. The bands are: under 40 bits Weak, 40–59 Fair, 60–79 Strong and 80 or more Very Strong. Because the estimate depends only on length and pool size, it is a fair measure for a randomly generated password, not for one you have edited by hand.
Use it when you create a new account, set a Wi-Fi or router password, or need a database credential. For a router password printed on a label, tick Exclude Ambiguous so nobody confuses 0 with O or l with 1. Paste the result straight into your password manager. If you need many random values at once, try the Random String Generator; for UUIDs and API-key style tokens, use the Random Token Generator.
How to use the Password Generator
- 1
Set the length
Drag the Length slider anywhere from 4 to 64 characters. A new password is generated as you move it.
- 2
Choose character types
Tick Uppercase, Lowercase, Numbers and Symbols as needed, and Exclude Ambiguous if the password will be read or typed from paper.
- 3
Check the strength
Read the Strength label and the bit estimate under it. The line below shows the length and pool size used for the calculation.
- 4
Copy and store it
Click the copy icon next to the password and paste it into your password manager. Click Generate New Password for a different one.
What it can do
Cryptographic, unbiased randomness
Uses crypto.getRandomValues with rejection sampling, so no character is more likely than another.
Every ticked type included
Passwords that miss a ticked character type are discarded and drawn again, which satisfies sites that demand a digit or symbol.
Transparent strength estimate
Shows bits of entropy from length × log2(pool size), along with the numbers used in that calculation.
Exclude ambiguous characters
Removes 0, O, I, l, 1 and | from the pool for passwords that people must read or type by hand.
Generated locally
Nothing is sent over the network or stored; the password exists only on the open page.
Limitations
- It makes one password at a time. For a list, use the Random String Generator.
- The symbol set is fixed: ! @ # $ % ^ & * ( ) _ + - = [ ] { } | ; : , . < > ?. If a site rejects one of them, untick Symbols or generate again.
- It does not create word-based passphrases.
- The strength figure describes how the password was generated. It no longer applies if you edit the password, and it says nothing about how a website stores it.
- Nothing is saved. Store the password before you close or reload the page.
Privacy
Passwords are generated by JavaScript in your browser using the Web Crypto API; they are not sent to FlexyPdf's servers, logged or stored.
Frequently asked questions
Is it safe to create a password on a website?
Here the password is created by code running in your own browser tab, and no request is made when you generate one. Even so, use a device you trust and save the password in a password manager rather than in a note or chat.
How is the strength in bits calculated?
Bits = length × log2(number of characters in the pool). With all four types ticked the pool has 88 characters, so each character adds about 6.5 bits and 16 characters give about 103 bits. With Exclude Ambiguous on, the pool drops to 82 characters.
Will the password always contain a number and a symbol?
Yes, when those types are ticked and the length is at least the number of ticked types. Any password missing a ticked type is thrown away and a new one is drawn.
How long should my password be?
Length adds strength faster than extra character types. Around 16 characters with mixed types gives about 100 bits here, comfortably in the Very Strong band; for important accounts such as email or banking, going longer costs you nothing if a password manager fills it in.
What does Exclude Ambiguous remove?
The characters 0, O, I, l, 1 and |, which are easy to confuse in many fonts. It is useful for passwords printed on labels, read aloud over the phone or typed from paper.
Ratings & Reviews
Rate Password Generator
Help others by sharing your experience. Your rating is shown without your name.
More Generators
View all →Random String Generator
Generate up to 100 random strings from letters, digits, hex or your own characters
QR Code Generator
Turn a link or any text into a QR code and save it as PNG or SVG
Barcode Generator
Make Code 128, EAN-13, EAN-8, UPC-A, Code 39 and ITF-14 barcodes
Countdown Timer
Count down from any time or a preset, with pause, reset and a beep at the end