Security

Password Generator

Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.

Last reviewed by the Radiatus Cloud team

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Randomness has to be cryptographic

Most password generators written in a hurry use Math.random(), which is a fast pseudo-random generator that is not seeded unpredictably and is not designed to resist prediction. Given enough output an attacker can reconstruct its internal state and derive every password it will produce. This tool uses crypto.getRandomValues(), the browser's cryptographically secure source, and rejects characters using unbiased sampling rather than a modulo that would quietly favour part of the alphabet.

Length beats complexity

Password strength is measured in entropy, roughly the base-2 logarithm of the number of equally likely possibilities. Each additional character multiplies the search space, while adding a symbol class only widens the base. A 20-character lowercase-only password has more entropy than a 10-character password using every class, and it is far easier to type. When you have to choose, choose length.

Complexity rules that force one uppercase, one digit and one symbol tend to backfire, because people satisfy them predictably: capitalise the first letter, append a digit and an exclamation mark. Cracking tools model that behaviour directly. NIST's own guidance moved away from mandatory composition rules for exactly this reason.

Passphrases

A passphrase of several random words from a large list is easy to remember and can carry substantial entropy: roughly 12.9 bits per word from a 7,776-word Diceware list, so six words is about 77 bits. The critical word is random. Words you chose yourself, or a phrase from a book or song, carry almost no entropy because they follow the statistics of language. Use the generated selection, not one you talk yourself into.

Ambiguous characters

The option to exclude visually similar characters exists because l, 1 and I, and 0 and O, are routinely misread when a password is transcribed. Excluding them shrinks the alphabet slightly, which you compensate for with one or two extra characters. For a password only ever pasted from a manager, leave them in.

Where the password goes next

A strong unique password per site is only manageable with a password manager. Reuse is the actual failure mode in most account compromises: a breach at one site becomes credential stuffing everywhere else. Generate, store it in a manager, and enable multi-factor authentication where offered.

Nothing leaves the browser

Generation happens locally. No password is transmitted, logged or stored, and there is no server-side component that could keep a copy. That is the only acceptable design for a tool of this kind.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
  • JWT Decoder — Decode JWT header and payload, inspect claims and expiry, and spot common security flaws. Runs locally, your tokens are never transmitted.

Frequently Asked Questions

Are the generated passwords sent anywhere?

No. They are generated in your browser with the Web Crypto API and never transmitted, logged or stored. There is no server-side component that could retain a copy.

How long should a password be?

Sixteen characters or more for an account that matters, and longer where the site permits. Length contributes more entropy than character variety, so a long password from a smaller alphabet beats a short one using every symbol class.

Is a passphrase better than a random string?

It is a different trade. A six-word random passphrase carries around 77 bits of entropy and is far easier to type and remember. A random string of equivalent strength is shorter but impractical to memorise. Use a passphrase where you must recall it, a random string where a manager stores it.

Why avoid Math.random for passwords?

It is a pseudo-random generator built for speed, not unpredictability. Its internal state can be reconstructed from enough output, letting an attacker derive past and future values. Cryptographic randomness from crypto.getRandomValues has no such weakness.

Should I change passwords regularly?

Not on a schedule, absent evidence of compromise. Forced rotation pushes people toward predictable variations. Current NIST guidance recommends changing a password when there is reason to believe it has been exposed, not every ninety days.

Privacy & Security

No data is stored. Passwords are generated client-side.

Data: None
Client-side-Side
Active
v1.0

How to Use

Select password length and characters options, then click Generate.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.