🔐 Password Generator

Generates random passwords using crypto.getRandomValues() — your browser's cryptographic random number generator. Nothing is sent anywhere; refresh the page and every password is gone.

How the bits are counted

With all four sets ticked the pool is 88 characters: 26 lowercase, 26 uppercase, 10 digits and the 26 symbols !@#$%^&*()-_=+[]{};:,.<>?/. Characters are drawn with rejection sampling, so there is no modulo bias, and the badge reports:

bits = length x log2(pool)
16 x log2(88) = 16 x 6.4594 = 103 bits

Excluding the ambiguous l 1 I O 0 trims the pool to 85 and costs 0.05 bits a character: 102.6 instead of 103.4 over 16 characters. Cheap, if you will ever read the password off a screen.

The two option checkboxes

No password is transmitted, logged or stored - the page makes no network call after it loads, and reloading loses everything on screen. Paste straight into your password manager rather than into a notes app.

Frequently asked questions

How long should a random password be?

16 characters from the full pool is 103 bits, beyond any offline attack. 12 gives 78 bits and is fine for ordinary accounts. Below 10 you are in range of rented GPUs against a fast hash.

Is it safe to use a password generator in a browser?

The randomness is sound: crypto.getRandomValues() is the operating system CSPRNG, not Math.random(). What no web page can promise is the machine around it - extensions, clipboard history and screen recorders see whatever you generate.

Why do sites still demand a capital and a symbol?

Habit. NIST removed composition rules from SP 800-63B because they push people to predictable patterns like Spring2024! rather than genuine randomness. Tick the box when a site insists, and add length instead when it does not.