Tools

Password generator

Random passwords from your browser's cryptographic generator. Nothing is sent to our server.

 

 

Characters to use

The password is created on your device. We never see or store it.

(02) — Details

Why generate a password instead of making one up

A made-up password is almost always predictable: a name, a birth year, a company name, “Qwerty” with an exclamation mark at the end. Attackers try these first, using dictionaries built from past leaks. A random string never appears in those dictionaries, so the only way in is blind guessing.

Length matters more than cleverness. Every extra character multiplies the number of options, so 16 random characters beat 10 characters with letters swapped for look-alike digits.

How this generator works

The password comes from your browser's cryptographic random number generator (the Web Crypto API). Nothing goes to our server: once the page has loaded you can go offline and keep generating.

Every password contains at least one character from each set you ticked: if digits are on, there will be a digit. The “no look-alikes” option removes 0 and O, 1, l and I, which helps when a password has to be read off a screen or dictated.

Where to keep passwords

In a password manager: KeePassXC, Bitwarden, 1Password or the one built into your browser. Not in phone notes, a file on the desktop or a chat: messages and email get read when an account is hacked, on a shared device or after an employee leaves.

Use a separate password for every service. Then a leak at one site does not unlock the rest of your accounts.

Passwords for your website's admin panel

Websites are often broken into through a guessed password for the admin panel, FTP or hosting control panel. The minimum worth doing:

  • a unique password of 16+ characters for everyone who logs into the admin panel;
  • two-factor authentication wherever it is available;
  • a separate account for each employee and contractor instead of one shared login;
  • access removed on the day a person stops working with you.

Passwords do not belong in the site's code or repository. If the database password is written into project files, anyone with a copy of the code gets the database too.

(03) — Questions

Questions.

Is it safe to generate a password online?
On this page, yes: the password is created in your browser and never transmitted. You can check it yourself: open developer tools, go to the Network tab and press the button a few times. No new requests will appear. Be careful with unknown generators: if the server creates the password, it can also keep it.
How long should a password be?
At least 12 characters for everyday accounts. At least 16 for email, banking, your website's admin panel and hosting. If the password lives in a manager and you never type it, go for 20–32 characters.
What do the bits in the strength rating mean?
That is entropy: password length multiplied by log₂ of the character set size. Every bit doubles the number of options. 80 bits is about 10²⁴ combinations, far too many to guess blindly.
Why remove look-alike characters?
So that 0 and O, 1, l and I are not confused when a password is read off a screen, copied from paper or dictated over the phone. The character set gets a little smaller, so add a couple of characters of length to keep the same strength.
Why are there no spaces or non-Latin letters?
Some sites and apps trim spaces or reject non-Latin letters, and such a password is hard to type on a different keyboard layout. Latin letters, digits and common symbols work everywhere.
(04) — Studio

Website passwords sitting in a chat or with a former contractor?

We will gather access to your site, hosting and domain in one place, change the passwords and close unused entry points. If the site has already been hacked, we will clean it up and find how the attacker got in.