Skip to content
TNToolsNexus

Password generator

Cryptographically random passwords with length and character-type controls, a live strength meter, and a look-alike filter — generated on your device.

Character types

Generated with your browser's cryptographic randomness, on your device — no password ever travels anywhere.

Generate cryptographically random passwords — 8 to 64 characters, with independent control of lowercase, uppercase, digits, symbols, and look-alike exclusion — using your browser’s own secure random source. Nothing is transmitted or saved.

How to generate a password

  1. Set the length — 16 is a strong default; go longer where sites allow it.
  2. Toggle character types. Every selected type is guaranteed to appear at least once, so a “must contain a symbol” form never rejects the result.
  3. Enable Avoid look-alikes if the password will be read or typed by a human (Wi-Fi setup, a printed recovery sheet) rather than pasted.
  4. Copy — or hit Regenerate until you get one you like. Each press is a fresh draw.

Why random beats clever

Human-invented passwords cluster: a capitalized word, a memorable number, a ! at the end. Cracking software tries exactly those shapes first — dictionary words with common substitutions and appended years fall in seconds, regardless of length. A random draw has no shape to exploit, so an attacker’s only move is brute force through the whole space. That space grows multiplicatively: each character from the full 94-symbol set adds about 6.6 bits of entropy, and every ~10 bits multiplies the required guesses by a thousand. The meter under the output shows this live — it is the same estimator as our password strength checker.

One password per account — let software remember them

The strongest password in the world protects nothing if it also unlocks four other accounts: when any one site is breached, attackers replay the leaked password everywhere (“credential stuffing”). The workable system is a password manager — the one built into your browser or a dedicated app — holding a unique random password per site, protected by one long passphrase you actually memorize plus two-factor authentication. Generate here, store there, memorize almost nothing.

Private by design

Generation runs entirely on your device using the browser’s cryptographic random source. No password, setting, or keystroke is uploaded, logged, or stored — there is no server side to trust, and the network tab will show nothing leaving.

Last updated:

Frequently asked questions

Is this generator actually random?
Yes — it uses your browser's crypto.getRandomValues(), the same operating-system-seeded cryptographic source that secures TLS connections. It also uses rejection sampling rather than a modulo shortcut, so no character in the set is ever statistically favored over another.
What length should I pick?
For anything that matters, 16+ characters with all four types, which lands comfortably in the very strong band. If a site caps length or bans symbols, compensate with length — 20 mixed-case letters and digits beat 12 characters of everything.
What does "Avoid look-alikes" do?
It removes 0/O/o, 1/l/I, and the pipe character from the pool — characters that are hard to tell apart when a password must be read off a screen or typed from paper. Skip it when you will only ever paste from a manager; the extra characters add a little entropy.
Could this password have been generated for someone else before?
A 16-character password from the full 94-character set is one of about 10³¹ possibilities. The chance any two generations ever collide is so far below lottery odds that it is treated as zero in practice.
Is the password sent to a server or stored?
No. It is generated by your own browser and exists only on your screen and clipboard. This page makes no network requests with your data — you can confirm that in your browser developer tools.

Related tools

Password Strength Checker

Estimate password strength honestly: entropy bits, an offline crack-time estimate, and specific pattern warnings — checked locally, never transmitted.

UUID Generator

Generate 1–100 cryptographically random version-4 UUIDs — uppercase and no-hyphen options, copy all in one click. Local, private.

Hash Generator (SHA)

SHA-256, SHA-1, SHA-384, and SHA-512 of any text or file — with a paste-to-compare checksum verifier. Runs locally, nothing uploaded.