Security Tool

Password Generator

Create strong random passwords with your preferred length and character types.

Published by Calculator All-in-OneMethod: local password generationMethods and limitations

What this calculator does

The Password Generator creates a random password based on length and character options. Strong passwords are long, unpredictable, and different for every account. The tool can mix lowercase letters, uppercase letters, numbers, and symbols based on site rules.

Generation happens entirely in your browser: the page builds a character pool from the options you tick, then draws random characters until the requested length is reached. Nothing you generate is transmitted or stored by the site, so each result exists only on your screen until you copy it.

When to use it

Use it when creating a new account, updating a weak password, setting up an admin login, creating a Wi-Fi password, or replacing a reused password. Store generated passwords in a trusted password manager.

Use it whenever a new credential is needed: fresh accounts, password rotations after a breach notification, router or Wi-Fi admin passwords, or one-off shared logins. The generated string should go straight into a password manager — the point of random passwords is that they are unmemorable, and reusing one across sites cancels the benefit.

How characters are selected

The generator requires the browser's cryptographic random-number API. It selects at least one character from each enabled group, fills the remaining positions from the combined pool, then shuffles the result. Random indexes use rejection sampling to avoid favoring some characters through rounding.

If secure random generation is unavailable, the tool shows an error and does not produce a weaker substitute. It does not calculate a guaranteed cracking time: account defenses, password storage and the attacker's access all affect security.

Understanding each option

  • Length — the number of characters. Twelve is a reasonable floor today; sixteen or more is better for anything important, and long passwords cost you nothing when a manager fills them.
  • Uppercase — adds A–Z to the pool, and satisfies the “mixed case” rule many sites enforce.
  • Numbers — adds 0–9.
  • Symbols — adds punctuation characters. Enable it unless a specific site rejects symbols; a few legacy systems do.

Check your output

With length 16 and every option enabled, the output has 16 characters and includes lowercase, uppercase, a digit and a symbol. With all optional groups disabled, it contains only lowercase letters. The selected length stays the same.

Each click generates a new result. Save a password before leaving this page; generating again will not recover the previous one.

Benefits

  • Create unique passwords
  • Match account rules
  • Avoid weak patterns
  • Generate quickly
  • Support password-manager workflows

Compared with inventing passwords, generation removes the human patterns attackers exploit first — names, dates, keyboard walks, and the word-plus-year format. It also makes rotation painless: replacing a credential is one click and one paste, not a creative exercise.

Using the result safely

Store the result in your password manager before closing this page. If a site rejects a character, adjust the options and generate again. Use a different password for each account and enable the account's additional authentication options. Random generation does not protect a password after it is disclosed.

Assumptions and limitations

The generator uses the browser's randomness and standard character pools. It does not check a site's specific composition rules (some ban certain symbols or cap length), does not screen against breached-password lists, and cannot protect a password that is later phished or reused. Strength estimates assume the attacker must brute-force, which is only true when the password is unique.

Common mistakes

  • Generating a strong password and then storing it in a plain text file or chat message.
  • Trimming a long password down to something memorable, which removes most of its entropy.
  • Reusing one generated password across several sites because it “looks strong”.
  • Skipping symbols out of habit when the site actually allows them.

FAQs

Should I reuse passwords?

No. Use a different password for every important account.

Where should I store passwords?

Use a reputable password manager.

Are longer passwords better?

Generally yes. Length makes random passwords harder to guess.

Do all sites allow symbols?

No. Adjust options to match site rules.

Can this guarantee security?

No. Strong passwords help, but two-factor authentication and safe habits also matter.

Protecting the generated password

The password generator is a browser utility for creating stronger random strings. Password strength also depends on storage, reuse, phishing resistance, account recovery, and whether a reputable password manager or two-factor authentication is used.

Use a generated password without weakening it

Length and character groups answer different questions

The length control sets how many characters appear. The checkboxes choose which additional character groups are available alongside lowercase letters. Enabling numbers does not mean that a password consists only of numbers. For example, a sixteen-character result is sixteen characters regardless of whether punctuation is included. A service may impose a maximum length or forbid particular symbols, so check its published requirements before selecting the groups.

Removing characters to make a generated password easier to type changes the result you asked the generator to produce. If the receiving service rejects it, choose compatible settings and generate a fresh value. Do not reuse a shortened fragment from a password already used elsewhere. The generator cannot inspect another service's password rules or verify that the service accepts the result.

Avoid accidental disclosure during copying

Treat the visible result as sensitive once you plan to use it for an account. A screen recording, screenshot, shared display, or clipboard-history tool can expose it independently of how the random characters were created. Copy it into the intended password field or a password manager and verify that the complete value was captured. Leading or trailing spaces accidentally included during manual selection may cause a login mismatch.

Generation is local to the browser, but the surrounding device environment still matters. This page does not audit extensions, clipboard software, screen-sharing applications, or the destination account. A locally generated secret can still be disclosed after generation. Avoid saving a usable password in an ordinary notes document shared with other people.

Match the tool to the task

Use a distinct password for each account and use the service's additional authentication options where appropriate. Random generation helps create a candidate secret; it does not create an account, change an existing password, or verify a successful reset. After completing a reset, confirm access through the service's normal login flow. If you suspect a password has been disclosed, replace it through that service rather than only pressing Generate again on this page.