Are generated passwords sent or saved anywhere?
No. They are generated in your browser with crypto.getRandomValues and never stored, sent, or put in a link. Only your option choices (length, sets) are remembered on this device.
Generate strong passwords, EFF-wordlist passphrases and developer secrets (hex, Base64URL, UUID v4, prefixed API keys) with crypto.getRandomValues and exact entropy.
Loading Password Generator…
Loading Password Generator…
Most password generators are fine; the details are where they differ. This one generates three kinds of secret. Passwords from 8 to 128 characters with any mix of lowercase, uppercase, digits and symbols, a custom symbol set for systems that only allow some, an option to drop look-alike characters, and an optional guarantee of at least one character from each set. Passphrases from the EFF Large Wordlist, with your choice of word count, separator, capitalization and an extra digit. And developer secrets: hex and Base64URL values of 16, 32 or 64 bytes, UUID v4, and prefixed API keys like sk_test_…. Everything comes from crypto.getRandomValues with rejection sampling, so there is no modulo bias, and "at least one of each" characters are shuffled into random positions with an unbiased Fisher–Yates shuffle. The entropy shown is computed for your exact settings, including the effect of required sets. Generate up to 100 at once and copy or download them. Generated values are never stored or shared.
Random 32-bit values come from crypto.getRandomValues. To pick one of n options, values at or above the largest multiple of n below 2^32 are discarded and redrawn, so every option has exactly the same probability. The same routine drives the shuffle and the word choice.
Without required sets, entropy is length × log2(alphabet size). With "at least one of each", the number of possible passwords is counted exactly with inclusion–exclusion (all strings minus those missing a set), and entropy is log2 of that count. Passphrase entropy is words × log2(7,776), plus the digit and its position if added.
The EFF Large Wordlist has 7,776 words chosen to be memorable and distinct, designed for five dice rolls per word. It is bundled with the page (credited to the Electronic Frontier Foundation, CC BY 3.0 US) and loaded only when you switch to passphrases.
Hex and Base64URL encode raw random bytes (Base64URL without padding is safe in URLs, headers and environment variables). UUID v4 sets the version and variant bits on 16 random bytes, leaving 122 random bits. API keys use a Base62 body after your prefix.
Short answers for the things developers usually ask before trusting a tool.
No. They are generated in your browser with crypto.getRandomValues and never stored, sent, or put in a link. Only your option choices (length, sets) are remembered on this device.
Every character or word is chosen with the Web Crypto API's cryptographically secure random generator, using rejection sampling so each option is exactly equally likely — the common "random byte % 62" shortcut makes some characters more likely than others. Math.random is never used. The test suite checks the distribution with a chi-square test over 100,000 characters per set.
For a password protected by a slow hash (bcrypt, Argon2) and rate-limited logins, 60+ bits is solid. For something that could be attacked offline with a fast hash, aim for 80+. Machine secrets like API keys and JWT signing keys should be 128–256 bits — a 32-byte random value.
Yes, when the words are chosen randomly. Each word from the 7,776-word EFF list adds 12.9 bits, so six words give 77.5 bits — about the same as a random 12-character password using all four character sets, and much easier to type and remember. What makes them weak is choosing the words yourself.
Slightly — it removes the combinations that miss a set — and the entropy shown accounts for that exactly. The required characters are shuffled into random positions, so they don't always appear at the start as with some generators.
Use at least 128 bits of randomness and a recognizable prefix like sk_live_ — the prefix lets secret scanners (GitHub, GitGuardian) detect leaked keys and tells humans what the key is for. Store only a hash of the key on the server, like a password.
Useful follow-ups when one conversion usually turns into three more.
Generate UUID v1, v4, and v7 in bulk, or validate and inspect any UUID.
Generate MD5, SHA-1, SHA-256, SHA-384, and SHA-512 hashes from text.
Hash a password with bcrypt at cost 4–15, verify a password against a $2a$/$2b$/$2y$ hash, and inspect a hash's version, cost and salt. Runs in a worker; nothing is stored.