Password Generator
Browser-based generationAdvanced options
Removes O, 0, I, l and 1. Useful when you may need to read or type the password manually.
crypto.getRandomValues(). It does not submit generated passwords, place them in the URL, or store a password history in localStorage or sessionStorage.
How to use the random password generator
The generator is built for a short workflow: choose the settings you need, generate a password, then copy it into the account or password manager where you plan to use it.
Use the slider or number field. The default is 20 characters, but you can choose 4 to 128 to match a site’s limits.
Turn uppercase letters, lowercase letters, numbers and symbols on or off. At least one type must remain selected.
Exclude hard-to-read characters, change the allowed symbol set or remove specific characters that a website rejects.
Each click draws fresh random values from the browser’s cryptographic random source. If several character types are selected, every generated password contains at least one character from each selected type.
What makes a random password strong?
A strong generated password starts with unpredictability. If characters come from a cryptographically strong random source, an attacker cannot rely on human habits such as names, birthdays, keyboard patterns or predictable substitutions. Length matters too because each added random character expands the number of possible combinations.
This tool does not claim that any password is “unhackable.” Account security also depends on how a service stores credentials, whether the same password is reused, whether phishing or malware is involved and whether extra protections such as multi-factor authentication are enabled.
Current guidance: NIST’s current digital identity guidance sets a 15-character minimum when a password is used as a single authentication factor. Some services still use different limits and composition rules, so the generator lets you customize length and character types rather than enforcing one policy for every account.
Password length and character sets
For a randomly generated password, more length means more possible strings. Character variety can increase the space further and may also satisfy older website rules that require an uppercase letter, number or symbol. Length, randomness and uniqueness are more useful concepts than trying to “humanize” a password with predictable substitutions.
| Setting | What it changes | When it helps |
|---|---|---|
| Length | Adds more random positions to the password | Usually the most direct way to increase the number of possible combinations |
| Uppercase/lowercase | Adds letter cases to the allowed set | Useful for sites that accept or require mixed case |
| Numbers | Adds digits 0-9 | Useful when an account policy requires numbers |
| Symbols | Adds selected punctuation | Useful for policy compatibility and additional character variety |
| Exclude ambiguous | Removes O, 0, I, l and 1 | Helpful when passwords must be read aloud or typed manually |
| Exclude characters | Removes exactly the characters you specify | Helpful when a service rejects specific characters |
How this secure password generator works
The JavaScript uses crypto.getRandomValues(), the browser’s cryptographic random-number interface. Character indexes are chosen with rejection sampling rather than a simple modulo operation, which avoids modulo bias when the character-set size does not divide the random-number range evenly.
When you select several character types, the generator first chooses one secure random character from each required set. It fills the remaining positions from the combined allowed set and then applies a Fisher-Yates shuffle driven by the same secure random integer function. That prevents required character types from appearing in fixed, predictable positions.
Why the tool does not use Math.random()
Math.random() is useful for many visual or casual tasks, but it is not intended as a cryptographic random source. A password generator should not quietly fall back to it. If the Web Crypto API is unavailable, this page shows an error instead of generating a weaker password.
What happens to generated passwords?
The generator itself does not send generated password values to a backend endpoint and does not keep a persistent history. Clearing or reloading the page removes the displayed values. Clipboard behavior is controlled by your browser when you press Copy.
Random password vs. passphrase
A random password is a string generated from characters such as letters, numbers and symbols. A passphrase usually combines multiple words into a longer secret that may be easier to type or remember. They solve slightly different problems. This page is focused on machine-generated random passwords, not human-created passphrases.
If a password manager will store and autofill the value for you, a long random password is usually practical because you do not need to memorize it. When you must remember a credential yourself, a suitably long passphrase can be easier to recall, but it still needs to avoid obvious quotations, personal facts and predictable word choices.
Password security tips
- Use a different password for every important account. Reuse turns one exposed password into a risk across multiple services.
- Store long random passwords in a reputable password manager rather than trying to memorize dozens of them.
- Enable multi-factor authentication or passkeys when a service supports them.
- Do not paste an existing real password into random websites to “test” its strength.
- If a site rejects a generated password, adjust the allowed symbols or length instead of weakening every other setting unnecessarily.
Related calculators and tools
These pages already exist on Statistics Fundamentals and are the closest matches to randomization, combinations and password-related math.
Frequently asked questions
Is this random password generator secure?
The generator uses the browser’s Web Crypto API rather than Math.random(), and it uses unbiased random integer selection plus a secure shuffle. That makes it suitable for generating random password strings in modern browsers. No generator can guarantee the security of the account where the password is used.
Are generated passwords stored?
Not by this generator. It does not write generated passwords to localStorage or sessionStorage and does not maintain a password-history feature.
Does the password leave my browser?
The generator code does not submit generated values to an API or backend endpoint. Copying a password uses your browser’s clipboard feature. Site-wide third-party scripts should still be reviewed before making broader privacy claims about the full production page.
How long should my password be?
There is no single length that fits every website. NIST’s current guidance requires at least 15 characters when a password is the only authentication factor. A longer random password provides more possible combinations, but the website’s own maximum length and allowed characters still matter.
Should I include symbols?
Symbols can increase the available character set and may satisfy a website’s password policy. They are not a substitute for length, randomness or uniqueness. If a site rejects certain punctuation, use the custom symbol field.
What are ambiguous characters?
They are characters that can be hard to distinguish visually, such as uppercase O and zero, or lowercase l and the number 1. Excluding them is useful when you expect to type the password manually.
Can I generate several passwords at once?
Yes. Choose 5, 10 or 20 from the “How many?” menu. Every password is generated with fresh cryptographic randomness.
Why does the generator guarantee selected character types?
If you select uppercase, lowercase, numbers and symbols, many websites expect at least one of each. The generator deliberately includes one random character from every selected type, then securely shuffles the result so those characters do not appear in predictable positions.
Sources and further reading
For current password policy guidance, see the NIST Digital Identity Guidelines, NIST’s password guidance for users and the OWASP Authentication Cheat Sheet.