Password and Passphrase Generator

Create a strong random password, a memorable passphrase or a PIN, generated on your device and never sent anywhere.

Generated entirely in your browser using its cryptographic random source. Nothing is transmitted or stored.

People are bad at randomness. Asked to make up a password, most of us reach for a word we know, a year that matters, and a symbol at the end, which is exactly what cracking software is built to guess. A generator removes the human pattern completely.

This one makes three kinds of secret. A passphrase is several random words, easy to type and surprisingly strong. A random password is a string of mixed characters, ideal when a password manager remembers it for you. A PIN is for devices and cards that lock after a few wrong attempts. Pick the one that matches how the secret will be used.

How it works

  1. Randomness comes from crypto.getRandomValues, the same cryptographic random source browsers use for secure connections. Ordinary Math.random is not used anywhere.
  2. Values are drawn with rejection sampling, which avoids the small bias that simple remainder maths introduces, so every character or word is equally likely.
  3. Passphrases pick words from the Electronic Frontier Foundation diceware lists. The short list has 1,296 words and the large list has 7,776.
  4. Random passwords guarantee at least one character from each type you ticked, then shuffle so the required characters are not in predictable positions.
  5. The strength shown is calculated from the size of the search space: for a passphrase, the number of words times the bits each word contributes.
  6. Your settings are remembered in this browser only, so the generator opens the way you like it next time. The passwords themselves are never saved.

Reading your results

  • Bits of strength measure how many guesses an attacker would need. Each extra bit doubles the work. 60 bits is strong for everyday accounts, and 80 or more suits a password manager master password or an encryption key.
  • A word from the short EFF list adds about 10.3 bits, and a word from the large list adds about 12.9 bits. Five large list words give roughly 64 bits, six give roughly 77.
  • A random 20 character password using all character types gives well over 100 bits, which is why it is the right choice when a password manager types it for you.
  • The crack time assumes the worst realistic case: a stolen database with a fast hash, attacked offline on a GPU rig at 10 billion guesses a second.
  • A PIN is weak by design. Four digits are only 10,000 combinations. It is safe only where the device locks or wipes after a few failed attempts.

How this fits into the real world

Your password manager master password and your main email account are the two secrets that protect everything else, and neither can be filled in by a manager when you first unlock it. That is the case a passphrase is built for: six random words are strong enough and you can actually type them on a phone.

For every other account, let the password manager generate and remember a long random string. You never need to see it, so there is no reason to make it memorable, and uniqueness per site means one breach cannot spread.

Security questions are a hidden weak point. Answers like your first school or your mother's maiden name are often findable online or in breach data. Use the generator to make a random answer, store it in your password manager, and treat it like a second password.

Wi-Fi passwords, disk encryption and backup encryption keys are also good uses for a long passphrase, because they are attacked offline where no lockout slows the attacker down.

Who this is for

  • Anyone setting up a password manager who needs one strong master passphrase they can remember.
  • People replacing a password that showed up in a breach check.
  • Anyone who needs random answers for security questions.
  • Small business owners setting shared Wi-Fi, admin or encryption passwords.

What this tool cannot tell you

  • A strong password does not help if you reuse it. Use each generated password on one account only.
  • It cannot protect you from phishing. If you type a strong password into a fake login page, the attacker has it. Two factor authentication and passkeys are the protection against that.
  • Some websites cap length or ban certain symbols. If a site rejects the password, shorten it or untick symbols rather than making it predictable.
  • The generator does not store anything, so copy the result into your password manager before you leave the page.

Frequently asked questions

Is a passphrase better than a password?

For secrets you must remember and type, yes. Five or six random words are easier to type accurately than a jumble of symbols and are just as hard to crack. For accounts a password manager fills in, a long random password is fine and slightly stronger per character.

How many words should a passphrase have?

Five words from the large list is a strong default for important accounts. Use six or seven for a password manager master password or anything that protects encrypted data. Four words is the minimum and only suitable where login attempts are limited.

Are online password generators safe to use?

Only ones that generate in your browser and send nothing. This page does exactly that, which you can confirm by disconnecting from the internet after the page loads: the generator keeps working. Avoid any generator that makes the password on a server.

What is the EFF wordlist or diceware?

Diceware is a method for building passphrases by rolling dice to pick words from a numbered list. The Electronic Frontier Foundation published improved lists in 2016 that avoid confusing, offensive and hard to spell words. This tool picks from those lists using a digital random source instead of dice.

How long should a password be in 2026?

At least 16 random characters for accounts a manager fills in, or at least five random words for a passphrase. Current guidance from NIST emphasises length over complexity rules and advises against forced regular changes unless a password has been exposed.

Should I use a different password for every account?

Yes. Reuse is how one breach turns into many hacked accounts. The only practical way to do it is a password manager, which remembers them all behind one strong passphrase.

Related tools

Guides that go with this tool