Skip to content
SPCXTools

Password Generator

Create strong, truly random passwords in your browser, with a live strength meter.

Runs locally — files never leave your device

Loading tool…

How to use Password Generator

  1. 1Drag the Length slider — 16 characters or more is recommended for most accounts.
  2. 2Choose which characters to include — uppercase, lowercase, numbers and symbols.
  3. 3Tick Avoid ambiguous characters if the password will be read or typed by hand.
  4. 4Check the strength meter, then click Copy. Press ↻ for a new password, or set How many to generate a batch.

Generate strong passwords you can trust

Weak and reused passwords are the most common way accounts are taken over. This password generator creates long, random passwords that are practically impossible to guess or brute-force. It uses your browser's cryptographically secure random number generator, and the passwords exist only on your screen — they are never sent over the network or saved anywhere.

Features

  • Length from 4 to 128 characters, adjustable with a slider.
  • Character sets: uppercase, lowercase, numbers and symbols, each guaranteed to appear at least once.
  • Avoid ambiguous characters to prevent confusing 0/O or 1/l/I.
  • Strength meter with entropy so you can see how strong a configuration really is.
  • Bulk generation of up to 50 passwords, handy when setting up several accounts or test users.
  • Unbiased randomness: values are drawn with rejection sampling, so every character is equally likely.

What makes a password strong

A password's strength depends on how many possibilities an attacker must try. That number is the size of the character pool raised to the power of the length. With all four character types enabled this tool draws from 88 characters, so each one adds about 6.5 bits of entropy:

Length Lowercase only (26) All four types (88)
8 38 bits 52 bits
12 56 bits 78 bits
16 75 bits 103 bits
20 94 bits 129 bits

Modern attackers can test billions of guesses per second against stolen password hashes, so aim for at least 80 bits for important accounts. As the table shows, adding length is the most effective way to get there.

Good password habits

  • Use a password manager to store a unique, generated password for every site. You then only need to remember one strong master password.
  • Turn on two-factor authentication wherever possible; it protects you even if a password leaks.
  • Don't modify old passwords by adding a number at the end — attackers' tools try those variations first.
  • Generate, don't invent. People are poor at randomness; names, dates and keyboard patterns are among the first things cracking tools test.

Need random numbers or IDs instead? Try the Random Number Generator or the UUID Generator.

Frequently asked questions

Are the passwords generated on your server?
No. Passwords are created in your browser with the Web Crypto API (crypto.getRandomValues), a cryptographically secure random number generator. They are never transmitted, logged or stored, and the tool keeps working if you disconnect from the internet after the page loads.
How long should my password be?
For online accounts, at least 14–16 random characters from all four character types. For a password manager's master password or encryption keys, use 20 or more — or a long passphrase you can remember. Length adds strength faster than complexity.
What does entropy in bits mean?
Entropy measures how many guesses an attacker would need. Each extra bit doubles the work. A random 16-character password using all four character types (88 possible characters here) has about 103 bits — far beyond what can be brute-forced. Below 60 bits is considered weak for anything important.
Why avoid ambiguous characters?
Characters like 0 and O, or 1, l and I, look alike in many fonts. Removing them prevents mistakes when a password is read aloud, printed or typed from another screen. It slightly reduces strength, which you can offset with a longer password.
Does every password include each selected character type?
Yes. The generator guarantees at least one character from every selected set and then shuffles the result, so it satisfies website rules such as "must contain a number and a symbol".
Should I reuse a strong password?
Never. If one site is breached, attackers try the same password everywhere. Use a different password for every account and store them in a password manager.