Password Generator
Generate secure, random passwords with customizable options for maximum security.
Generated Password
Password Options
How to use this tool
- Adjust the password length using the slider (4-64 characters)
- Select which character types to include: uppercase, lowercase, numbers, symbols
- Optionally exclude ambiguous characters like 0, O, l, 1, I
- Click 'Generate New Password' or the refresh button to create a new password
- Use the copy button to copy the password to your clipboard
About this tool
Password Generator creates cryptographically secure random passwords using the Web Crypto API. Strong passwords are essential for protecting your online accounts from brute force attacks and unauthorized access. This tool runs entirely in your browser - passwords are never sent to any server. For maximum security, use passwords with 16+ characters including all character types.
Frequently asked questions
What makes a password strong?
Length first, then unpredictability. Every extra character multiplies the work an attacker has to do, so a long password from a genuinely random source beats a short clever one every time. Sixteen characters with mixed types is a sound default; anything human-chosen is weaker than it looks because people pick from a small space.
Are these passwords really random?
They come from the Web Crypto API, which is your browser's cryptographically secure random number generator, not the ordinary pseudorandom function used for shuffling and animation. That distinction matters: only the cryptographic source is unpredictable to someone who has seen previous outputs.
Is it safe to generate a password on a website?
It depends entirely on where the generation happens. Here it happens in your browser, on your device, and the password is never transmitted anywhere. Nothing is sent to a server, so there is nothing on our side to log, store or leak. You can confirm this by disconnecting from the network and generating one.
Should I exclude ambiguous characters?
Only when the password will be read by a human and typed by hand, where 0 and O or l and 1 cause real trouble. It slightly reduces the character pool and therefore the strength, so leave them in for anything going straight into a password manager.
How often should I change my passwords?
Current guidance from NIST and the UK's NCSC is not on a schedule. Forced routine changes push people towards small predictable variations, which is worse. Change a password immediately if a service reports a breach, if you suspect compromise, or if you reused it somewhere else.
Should I use a different password for every account?
Yes, and it is the single highest-value habit available. Credential stuffing, where attackers replay one leaked email and password pair against hundreds of other sites, only works because passwords get reused. A password manager makes uniqueness practical without memorising anything.

