Skip to content
EVOA Toolbox

Password Generator

Create strong random passwords and passphrases with your browser's secure random generator. Choose length and characters, see the entropy. Never sent anywhere.

Processed locally in your browser. Your text is not uploaded.

Loading tool…

What this tool does

Generate random passwords from 4 to 128 characters using any mix of uppercase letters, lowercase letters, digits and symbols, or switch to passphrase mode for a memorable string of random words. You can exclude look-alike characters such as O, 0, I, l and 1, require at least one character from every selected set, and produce up to 20 passwords at once.

Randomness comes only from the Web Crypto API (crypto.getRandomValues), the same cryptographically secure source your browser uses for TLS keys. Characters and words are picked with rejection sampling, which discards values that would make some choices slightly more likely than others, so there is no modulo bias.

The strength meter shows entropy in bits: length multiplied by the base-2 logarithm of the pool size for passwords, or number of words times log2 of the list size for passphrases. The password is generated in your browser and is never sent to a server, stored, or logged. Even so, paste it straight into a password manager rather than leaving it on screen.

How to use it

  1. 1Choose Password or Passphrase mode.
  2. 2Set the length (or number of words) and the character sets, separator and options you need.
  3. 3Check the entropy and strength shown below. Longer is the simplest way to get stronger.
  4. 4Copy the result into your password manager. Press Regenerate for a new one.

Supported formats

Plain text passwords and passphrases. Nothing is saved or exported.

Privacy

Passwords are generated entirely in your browser with the Web Crypto API. They are not transmitted, stored or logged by this site.

Limitations

  • Entropy figures assume a uniformly random choice. With Require one of each enabled the true value is marginally lower than length × log2(pool).
  • The passphrase list has about 1,500 common words (roughly 10.5 bits per word). Use six or more words for important accounts. It is not the EFF list.
  • Strength labels refer to resistance to offline guessing of a random secret. They say nothing about a site that stores passwords badly or about phishing.
  • Some websites reject certain symbols or limit length. Turn symbols off or shorten the length if a site refuses the result.

FAQ

Is this password really random and private?

It uses crypto.getRandomValues, a cryptographically secure generator, and never Math.random. Everything runs locally; the password is not sent anywhere. You are still responsible for storing it safely.

How long should my password be?

For accounts protected by a password manager, 16-20 random characters is plenty. For something you must type or remember, a passphrase of 5-6 random words is strong and easier to recall.

What is entropy?

It is a measure of how many guesses an attacker would need on average. Each extra bit doubles the work. 80 bits or more is very strong against offline attacks on randomly generated secrets.

Why exclude ambiguous characters?

Characters like l, I, 1, O, 0 and o are easy to confuse when reading or typing a password by hand. Excluding them slightly reduces the pool, so add a character or two to compensate.

Are passphrases as secure as passwords?

Yes, when the words are chosen randomly. Four words from this list give about 42 bits, six words about 63, eight words about 84. Add more words to reach the strength you want.

Related tools