Skip to content
OmniTools

Password & passphrase Generator

Generate strong random passwords and passphrases, with an entropy estimate.

All developer tools

Password & passphrase generator

20 characters

This tool runs entirely in your browser. Nothing you enter is uploaded, stored, or logged.

What this tool does

A long random password is dramatically stronger than a short complicated one, because length adds security exponentially while added symbols add it only marginally. This tool generates passwords and readable passphrases from the browser's cryptographic random source, and reports the entropy in bits so the strength is a number rather than a guess.

How it works

Entropy measures how many guesses an attacker needs, and it depends on the size of the random pool and the length of the password. With 26 lowercase letters the pool is 26 per character, so each character adds about 4.7 bits. Including uppercase, digits, and symbols grows the pool and adds bits per character, but the effect is small next to simply adding characters.

To see the difference: an 8-character password from a 94-character pool has about 52 bits, which is far too low for anything important. A 16-character password from the same pool has about 105 bits, and a passphrase of five random words has over 100 bits while being easier to type and remember. Length is the cheapest security available.

Generation uses crypto.getRandomValues, and characters are drawn with modulo reduction against the pool size. Because a cipher's random bytes are not perfectly uniform, picking from a pool that does not divide 256 introduces a tiny bias, which this tool avoids by rejecting the tail of the range rather than folding it back.

Worked example

Comparing two candidate passwords against an offline attack.

  1. 8 characters from a 94-character pool: 94^8 ≈ 6×10^15, about 52 bits
  2. 16 characters from the same pool: ≈ 3.6×10^31, about 105 bits
  3. Five words from a 7,776-word list: 7776^5 ≈ 2.8×10^19, about 104 bits

The 16-character random password and the five-word passphrase are equally strong, but the passphrase is far easier to recall and type. Both are effectively impossible to brute-force offline.

Accuracy and limitations

  • The strength shown assumes the password is not found in a breached-password list. Reused passwords are cracked from lists in seconds regardless of their complexity.
  • A passphrase's real strength depends on the word list size. This tool uses a list of over two thousand common words, so a four-word passphrase is weaker than a five-word one.
  • Store passwords in a password manager. Do not rely on remembering them or on writing them down somewhere discoverable.

Frequently asked questions

How long should a password be?
For most accounts, 16 or more characters from a full character pool, or five or more random words as a passphrase. Length matters more than symbols. If the service supports it, a hardware key or an authenticator app removes the password problem entirely.
Is a passphrase as secure as a random password?
Yes, if the words are chosen at random rather than by you. Five words from a large list is over 100 bits, comparable to a 16-character random password, and far easier to type correctly and remember.
Do these passwords get sent anywhere?
No. They are generated in your browser from the cryptographic random source and never transmitted. Be careful where you copy them to, since any password you paste into an unknown site is no longer private to you.
Why exclude characters like quotes and backslashes?
Excluding a handful of visually ambiguous characters, and characters that break CSV, shell, and JSON contexts, does not meaningfully weaken a password from a long random list. It removes a large class of transcription errors instead.