BY: Statistics Fundamentals Team
Updated: October 3, 2026

Secure Random Password Generator

Create a strong random password with the length and character types you choose. Generation happens in your browser using the Web Crypto API.

Password Generator

Browser-based generation
Long random password
20 characters 4 character sets The generator does not save password history
Default: 20 characters. Short lengths are available for compatibility, not as a security recommendation.
Generate a small batch when you need several unique values.
Include character types
Advanced options

Removes O, 0, I, l and 1. Useful when you may need to read or type the password manually.

Used only when Symbols is selected. Duplicate symbols are automatically deduplicated.
Any characters entered here are removed from all selected character sets.

Generated passwords

Privacy note: The generator code creates passwords locally with crypto.getRandomValues(). It does not submit generated passwords, place them in the URL, or store a password history in localStorage or sessionStorage.

How to use the random password generator

The generator is built for a short workflow: choose the settings you need, generate a password, then copy it into the account or password manager where you plan to use it.

1
Choose a length

Use the slider or number field. The default is 20 characters, but you can choose 4 to 128 to match a site’s limits.

2
Select character types

Turn uppercase letters, lowercase letters, numbers and symbols on or off. At least one type must remain selected.

3
Adjust advanced options if needed

Exclude hard-to-read characters, change the allowed symbol set or remove specific characters that a website rejects.

4
Generate and copy

Each click draws fresh random values from the browser’s cryptographic random source. If several character types are selected, every generated password contains at least one character from each selected type.

What makes a random password strong?

A strong generated password starts with unpredictability. If characters come from a cryptographically strong random source, an attacker cannot rely on human habits such as names, birthdays, keyboard patterns or predictable substitutions. Length matters too because each added random character expands the number of possible combinations.

This tool does not claim that any password is “unhackable.” Account security also depends on how a service stores credentials, whether the same password is reused, whether phishing or malware is involved and whether extra protections such as multi-factor authentication are enabled.

Current guidance: NIST’s current digital identity guidance sets a 15-character minimum when a password is used as a single authentication factor. Some services still use different limits and composition rules, so the generator lets you customize length and character types rather than enforcing one policy for every account.

Password length and character sets

For a randomly generated password, more length means more possible strings. Character variety can increase the space further and may also satisfy older website rules that require an uppercase letter, number or symbol. Length, randomness and uniqueness are more useful concepts than trying to “humanize” a password with predictable substitutions.

SettingWhat it changesWhen it helps
LengthAdds more random positions to the passwordUsually the most direct way to increase the number of possible combinations
Uppercase/lowercaseAdds letter cases to the allowed setUseful for sites that accept or require mixed case
NumbersAdds digits 0-9Useful when an account policy requires numbers
SymbolsAdds selected punctuationUseful for policy compatibility and additional character variety
Exclude ambiguousRemoves O, 0, I, l and 1Helpful when passwords must be read aloud or typed manually
Exclude charactersRemoves exactly the characters you specifyHelpful when a service rejects specific characters

How this secure password generator works

The JavaScript uses crypto.getRandomValues(), the browser’s cryptographic random-number interface. Character indexes are chosen with rejection sampling rather than a simple modulo operation, which avoids modulo bias when the character-set size does not divide the random-number range evenly.

When you select several character types, the generator first chooses one secure random character from each required set. It fills the remaining positions from the combined allowed set and then applies a Fisher-Yates shuffle driven by the same secure random integer function. That prevents required character types from appearing in fixed, predictable positions.

Why the tool does not use Math.random()

Math.random() is useful for many visual or casual tasks, but it is not intended as a cryptographic random source. A password generator should not quietly fall back to it. If the Web Crypto API is unavailable, this page shows an error instead of generating a weaker password.

What happens to generated passwords?

The generator itself does not send generated password values to a backend endpoint and does not keep a persistent history. Clearing or reloading the page removes the displayed values. Clipboard behavior is controlled by your browser when you press Copy.

Random password vs. passphrase

A random password is a string generated from characters such as letters, numbers and symbols. A passphrase usually combines multiple words into a longer secret that may be easier to type or remember. They solve slightly different problems. This page is focused on machine-generated random passwords, not human-created passphrases.

If a password manager will store and autofill the value for you, a long random password is usually practical because you do not need to memorize it. When you must remember a credential yourself, a suitably long passphrase can be easier to recall, but it still needs to avoid obvious quotations, personal facts and predictable word choices.

Password security tips

  • Use a different password for every important account. Reuse turns one exposed password into a risk across multiple services.
  • Store long random passwords in a reputable password manager rather than trying to memorize dozens of them.
  • Enable multi-factor authentication or passkeys when a service supports them.
  • Do not paste an existing real password into random websites to “test” its strength.
  • If a site rejects a generated password, adjust the allowed symbols or length instead of weakening every other setting unnecessarily.

Related calculators and tools

These pages already exist on Statistics Fundamentals and are the closest matches to randomization, combinations and password-related math.

Frequently asked questions

Is this random password generator secure?

The generator uses the browser’s Web Crypto API rather than Math.random(), and it uses unbiased random integer selection plus a secure shuffle. That makes it suitable for generating random password strings in modern browsers. No generator can guarantee the security of the account where the password is used.

Are generated passwords stored?

Not by this generator. It does not write generated passwords to localStorage or sessionStorage and does not maintain a password-history feature.

Does the password leave my browser?

The generator code does not submit generated values to an API or backend endpoint. Copying a password uses your browser’s clipboard feature. Site-wide third-party scripts should still be reviewed before making broader privacy claims about the full production page.

How long should my password be?

There is no single length that fits every website. NIST’s current guidance requires at least 15 characters when a password is the only authentication factor. A longer random password provides more possible combinations, but the website’s own maximum length and allowed characters still matter.

Should I include symbols?

Symbols can increase the available character set and may satisfy a website’s password policy. They are not a substitute for length, randomness or uniqueness. If a site rejects certain punctuation, use the custom symbol field.

What are ambiguous characters?

They are characters that can be hard to distinguish visually, such as uppercase O and zero, or lowercase l and the number 1. Excluding them is useful when you expect to type the password manually.

Can I generate several passwords at once?

Yes. Choose 5, 10 or 20 from the “How many?” menu. Every password is generated with fresh cryptographic randomness.

Why does the generator guarantee selected character types?

If you select uppercase, lowercase, numbers and symbols, many websites expect at least one of each. The generator deliberately includes one random character from every selected type, then securely shuffles the result so those characters do not appear in predictable positions.

Sources and further reading

For current password policy guidance, see the NIST Digital Identity Guidelines, NIST’s password guidance for users and the OWASP Authentication Cheat Sheet.