Password & Passphrase Generator
Free password generator: strong random passwords or memorable EFF Diceware passphrases. See exact entropy and crack times under four attack scenarios.
Independent characters drawn from the classes you select. Shortest for a given strength, but you will not memorise it.
Random password: length against strength
All four character classes selected, an 85-character pool. Verdicts use the zxcvbn guess-count thresholds.
| Length | Entropy | Verdict |
|---|---|---|
| 8 characters | 50 bits | Very strong |
| 12 characters | 76 bits | Very strong |
| 16 characters | 102 bits | Very strong |
| 20 characters | 128 bits | Very strong |
| 24 characters | 154 bits | Very strong |
| 32 characters | 205 bits | Very strong |
Passphrase: words against strength
Drawn from the 7,776-word EFF long wordlist, so every word contributes 12.92 bits regardless of how long it is.
| Words | Entropy | Verdict |
|---|---|---|
| 3 | 39 bits | Very strong |
| 4 | 52 bits | Very strong |
| 5 | 65 bits | Very strong |
| 6 | 78 bits | Very strong |
| 7 | 90 bits | Very strong |
| 8 | 103 bits | Very strong |
Passphrase words: EFF's long wordlist, by the Electronic Frontier Foundation, licensed under CC BY 4.0.
Related Calculators
You might also find these calculators useful
Password Strength Calculator
Guess resistance, crack time and NIST 800-63B rev 4 checks
Time to Crack Password Calculator
Crack times by hash algorithm, work factor and GPU count
UUID & GUID Generator
Generate UUID v4, v6, v7, ULID and NanoID in bulk — or decode one.
SHA-256 & MD5 Hash Generator
Generate and verify SHA-256, MD5, SHA-1, SHA-512 and SHA-3 digests
Free Password & Passphrase Generator
Generate a strong random password or a memorable EFF Diceware passphrase, entirely in your browser. Every character comes from your device's cryptographic random source, never from Math.random, and nothing is stored, logged, or sent anywhere. What sets this generator apart is what it tells you afterwards: the exact size of the keyspace your settings can produce, and how long that survives against four named attackers — from a login form that allows a hundred tries an hour to a cracking rig running ten billion guesses a second.
What Makes a Generated Password Strong?
Strength is the size of the space the generator could have drawn from, measured in bits. Double the space and you add one bit; each bit doubles the work an attacker must do. Two things grow it: the number of options at each position, and the number of positions. That is why length beats complexity — adding one character to a 16-character password over an 85-character pool buys more than switching on an entire extra character class. Note that this is the keyspace of the process, not a guess at how memorable the result looks: a generated password has no pattern for an attacker to shortcut, which is exactly what makes the arithmetic below trustworthy.
Keyspace entropy
E = log₂(K), where K = number of passwords the settings can produceHow to Generate a Strong Password
Pick a preset, or choose between a random password and a passphrase.
Set the length — or the number of words — and choose which character classes to include.
Optionally exclude look-alike characters (I, l, 1, O, 0) if the password will be typed on a TV remote or read aloud.
Press Generate. Nothing appears until you do, so a password is never sitting on screen before you want one.
Read the verdict: the band, the crack time for a properly hashed password, and the entropy in bits.
Open the scenario table to see how the same password fares against a rate-limited login and against a cracking rig.
Copy it straight into your password manager — or generate a batch and export the list as CSV.
When to Use a Password Generator
New online accounts
A unique password per site means one breach unlocks one account. Sixteen random characters is comfortably past the point where guessing stops being the attacker's cheapest route.
Wi-Fi network keys
A long key without symbols or look-alike characters is far easier to type on a games console or read out to a guest, and the extra length more than pays back the smaller pool.
PINs and door codes
Six digits is only 20 bits, which is why it must be paired with a lockout. The scenario table shows exactly what that lockout is buying you.
Master passwords
The one secret you have to remember. A six- or seven-word passphrase is easier to recall than a random string and stronger than most people's best attempt at one.
Developers and administrators
Generate up to 50 credentials at once for test fixtures, seed data, or a service-account rotation, and export the batch as CSV.
Replacing a breached password
If a password has appeared in a breach corpus, its strength is irrelevant — it is already on a list. Generate a fresh one rather than editing the old one.
Why Use This Password Generator?
Cryptographically secure randomness
Every character and every word is drawn with crypto.getRandomValues, the browser's CSPRNG, using rejection sampling so no value is even slightly more likely than another. Math.random is never used — it is not designed to resist prediction.
The keyspace is counted, not estimated
Most generators print length × log₂(pool). That is only right when every position is a free draw. Switch on "no repeated characters" and the draws stop being independent; require one character from each class and whole strings become impossible. Both are counted exactly here, so the bits shown are the bits you got.
Four attackers, not one number
"Time to crack" means nothing without a guess rate. A six-digit PIN falls in under a second to an offline attack on a fast hash and holds for over a year behind a rate-limited login. Both figures are on screen.
Random or memorable
Switch between random characters and passphrases built from the EFF long wordlist — the same 7,776-word list the Electronic Frontier Foundation publishes for Diceware, shipped verbatim.
Nothing leaves your device
Generation is local JavaScript. No password is transmitted, saved, or shared, and none of them appears in any log we could be asked to hand over.
Consistent with our strength checker
This page and our password strength checker share one attack model and one set of band thresholds, so a password generated here gets the same verdict when you paste it there.
Password Generator FAQ
NIST SP 800-63B revision 4, section 3.1.1.2, requires a password used as the only authentication factor to be at least 15 characters, and at least 8 when it is used alongside another factor. Sixteen random characters from a full pool is about 103 bits, which is past any practical brute-force attack. Length is the lever that matters most: each extra character multiplies the work.
It depends on what you need to do with it. Each word from the EFF long wordlist contributes log₂(7,776) = 12.92 bits, so a six-word passphrase is about 77.5 bits — strong, and something you can actually say out loud. A 16-character random password reaches 103 bits in a quarter of the characters. Use a passphrase where you must remember or dictate it; use random characters everywhere your password manager does the typing.
A guess rate, which is the single largest variable in the whole calculation. This page shows four: 100 guesses per hour (a rate-limited login), 10 per second (an unprotected login), 10,000 per second (an offline attack on a slow hash such as bcrypt) and 10 billion per second (an offline attack on a fast unsalted hash). The headline uses the slow-hash figure, because that is what a competently run service gives an attacker who steals its database. The same password can differ by a factor of a million across those four.
Because the draws stop being independent. Without the option, each position is a free choice from the whole pool, so the count is pool^length. With it, each character used is removed from the pool for the next position, so the count is the falling factorial instead. At 16 characters over an 85-character pool that is a loss of about 2 bits; at 32 characters it is nearly 10. The figure shown is always the one that matches the option you chose.
Very slightly, and only at short lengths. Demanding at least one character from every selected class rules out every string that misses a class, which shrinks the space: about 3.8 bits at 4 characters, under 0.3 bits at 12 and above. It is included because many sites still enforce composition rules, and the cost is counted exactly rather than ignored.
A generator is safe when its randomness is cryptographic and it runs on your device. This one uses crypto.getRandomValues, the browser's own CSPRNG, and generates entirely in local JavaScript — there is no request to inspect and no server-side log. Be wary of any generator that sends what it produces over the network, whatever it promises about retention.
Diceware builds a passphrase by choosing words at random from a fixed numbered list, traditionally with physical dice. This page uses the EFF long wordlist — 7,776 words, five dice rolls each — published by the Electronic Frontier Foundation in 2016 and chosen so the words are easy to spell, easy to type and hard to confuse with one another. The list shipped here is byte-identical to the file EFF publishes.
Include them wherever the site allows, because they enlarge the pool: all four classes give 85 characters against 52 for letters alone, worth about 0.7 bits per character. But do not contort a password to satisfy a rule. NIST SP 800-63B-4 explicitly tells verifiers not to impose composition rules, precisely because they push people toward predictable substitutions like replacing a with @.
Up to 50 in one batch. Copy them all with one click, or download the batch as a CSV file — useful for seeding test accounts or rotating a set of service credentials. The batch is generated locally like everything else, and the CSV is written by your browser, not downloaded from us.
The characters I, l, 1, O, 0, o, the pipe and the backtick — the ones that are routinely misread in a sans-serif font or misheard when read aloud. It shrinks the pool, so the entropy shown drops accordingly; the trade is worth it for a Wi-Fi key or anything that gets typed on a remote control, and rarely worth it for a password your manager fills in.
No. NIST SP 800-63B-4 tells verifiers not to require periodic password changes, and to force one only when there is evidence the password has been compromised. Scheduled rotation reliably produces predictable increments rather than new secrets. Generate a fresh random password when something actually happens.
In a password manager. The whole argument for high-entropy passwords assumes you are not trying to remember them — which is why the one secret that should be a memorable passphrase is the manager's master password. Generate that here in passphrase mode, and let the manager hold everything else.
The two pages measure different things. This one reports the keyspace it drew from, which it knows exactly. The strength checker reports guessability: how few attempts an attacker who knows the common patterns would need, which for a truly random string is a deliberately conservative estimate. The verdict band and the crack times come from one shared model, so the two pages agree on the conclusion even where the bit counts differ.
No. 128 bits is the standard for a cryptographic key, which must resist an attacker who can try keys at hardware speed forever. A password is defended by a slow hash and a rate limit as well as by its own entropy. Once a password is past roughly 80 bits, the realistic risks are phishing, reuse and malware — not brute force — and extra length stops buying you anything.