Password Generator: Strong Random Passwords and Passphrases

Runs in your browser: nothing you enter or choose is uploaded.

What do you need?

This password generator makes either a random password, with the length and characters you choose, or a passphrase of random words from EFF’s short wordlist, using your browser’s secure random number generator. It shows the estimated strength in bits. It runs in your browser: nothing is uploaded or saved.

How to use the password generator

  1. Under What do you need?, choose Passphrase (easy to type and remember) or Random password.
  2. For a passphrase, set the Number of words (3 to 10, with 6 as the default) and choose what goes Between words: a hyphen, a space, a dot or nothing. Keep or untick Capitalise each word and Add a number.
  3. For a random password, set the Length (8 to 64, with 16 as the default) and tick the character sets to use: a–z, A–Z, 0–9 and symbols. Leave Skip look-alikes (0 O l 1) on if you’ll ever read or type it by hand.
  4. Press Generate. Press it again for a fresh one; nothing is stored.
  5. Save the result straight into your password manager, then use it on the site or app.

Passphrase or random password: which should you pick?

Both can be strong. The difference is who has to remember and type them. A random password packs the most strength into each character, which is ideal when your password manager fills it in for you. A passphrase is longer but far easier to type from memory or read out loud.

You need it forPickWhy
Most website and app logins, saved in a password managerRandom password, 16+ charactersYou never type it, so make it as strong as the site allows
Your password manager, computer or phone sign-inPassphrase, 6+ wordsYou’ll type it from memory, often several times a day
A site with strict rules (short maximum, no symbols)Random password with sets unticked to matchFit the site’s rules, then make it as long as allowed
Typing on a TV, console or someone else’s devicePassphrase, or a random password with look-alikes skippedFewer typing mistakes

How it works

Every word and character is picked with crypto.getRandomValues, the browser’s built-in source of cryptographically strong random numbers. That matters: everyday random functions such as JavaScript’s Math.random aren’t designed for security and shouldn’t be used to make passwords.

In passphrase mode, words come from the Electronic Frontier Foundation’s short wordlist of 1,296 words. That number is every possible result of rolling four dice (6 Γ— 6 Γ— 6 Γ— 6), and each word adds about 10.3 bits of strength. Five words give about 52 bits, six about 62 and seven about 72. Capitalising every word adds nothing, because an attacker who knows the method tries that too. A random number adds a little.

In password mode, strength is the length multiplied by the bits each character adds, which depends on how many characters are allowed. Letters in both cases plus digits give 62 possible characters, about 5.95 bits each, so a 16-character password is about 95 bits. Adding symbols raises that; skipping look-alikes removes a few characters and costs only a fraction of a bit per character.

Each extra bit doubles the number of guesses an attacker needs to try every possibility. The tool assumes the attacker knows exactly how the password was made (which list, how many words, which characters). That’s the honest way to measure it, and it’s why the figure is lower than some “strength meters” show.

How to read your result

Estimated strengthWhat it meansTypical example
Under 40 bitsWeak. Too easy to guess if a site’s password database leaksA 3-word passphrase
40–59 bitsFair. Fine for low-value accounts with two-step verificationA 5-word passphrase (about 52 bits)
60–79 bitsStrong. Good for passwords you must rememberA 6- or 7-word passphrase
80 bits and upVery strong. Beyond realistic guessingA 16-character random password
Our rule of thumb, not an official standard.

Why so much? When you log in to a website, it limits how fast anyone can guess. But if the site’s password database is stolen, attackers can test guesses offline at high speed. A long, unique password makes that slow enough to be pointless, and means a leak exposes only that one account.

How long should a password be?

The US National Institute of Standards and Technology (NIST) updated its digital identity guidelines, SP 800-63B Revision 4, in August 2025. It says services must require passwords of at least 15 characters when the password is the only thing protecting an account, and at least 8 when it’s combined with another factor such as a code or passkey. They should allow at least 64 characters.

NIST also tells services not to force mixes of character types, not to make you change passwords on a schedule (only when there’s evidence of compromise), to check new passwords against lists of common and leaked ones, and to allow password managers and pasting. The US Cybersecurity and Infrastructure Security Agency (CISA) recommends at least 16 characters, either a random string or a passphrase of 4 to 7 unrelated words.

Put together: use 16 or more random characters for passwords your manager stores, and 6 or more words for the few you must remember. A five-word passphrase with separators from this tool is already well over 15 characters.

Sites still set their own rules. Some cap the length, ban certain symbols or insist on a symbol. If a site rejects a password, read its rules, adjust the length or character sets here and generate a new one.

Keep your accounts safe beyond the password

  • Use a password manager. The one built into your phone or browser, such as Google Password Manager on Android or Apple’s Passwords app, can create, store and fill strong passwords. Then you only need to remember one strong passphrase.
  • Never reuse a password. One leaked site shouldn’t unlock your email, bank and social media.
  • Switch to passkeys where you can. A passkey can’t be guessed, reused or typed into a fake site. Our guide shows how to set up passkeys on Google, Microsoft and Apple accounts.
  • Turn on two-step verification for accounts that don’t support passkeys yet.
  • If an account is taken over, change that password and any place you reused it. Our guide to recovering a hacked Instagram account walks through the recovery steps.

More practical guides are in our security hub.

Limitations

  • The bits figure describes what the generator made. If you edit the result or swap in your own words, the estimate no longer applies.
  • Nothing is saved. If you close or refresh the page before storing the password, it’s gone.
  • A strong password can’t protect you from a phishing page or malware on your device. If you think a device is compromised, start with how to tell if your phone has been hacked.
  • Don’t generate passwords on a shared or public computer, where someone else may see the screen or what you copy.

FAQ

Is it safe to use an online password generator?

Only if it creates the password on your device with a secure random source and sends nothing anywhere. This one runs entirely in your browser using crypto.getRandomValues. Once the page has loaded it makes no network requests, so it keeps working offline.

How many words should a passphrase have?

Use at least 5 words from a wordlist like EFF’s, and 6 or more for important passwords you must remember, such as your password manager’s. CISA suggests 4 to 7 unrelated words.

Is a 16-character password strong enough?

Yes, if it’s random and unique. A 16-character password of letters and digits is about 95 bits, far beyond realistic guessing. CISA recommends at least 16 characters.

Should I change my passwords regularly?

Not on a schedule. NIST’s guidelines tell services not to force periodic changes. Change a password when there’s a sign it was leaked or someone else used your account.

Are passkeys better than passwords?

For most people, yes. A passkey can’t be phished, guessed or reused, and you unlock it with your fingerprint, face or PIN. Keep a strong, unique password as a backup where a site still requires one.

Sources