Random Password

Frequently asked questions

Safety, storage, length, and the choices behind the character sets.

Is it safe to generate a password on a website?

It depends entirely on where the generating happens. If a site builds the password on its server, the password exists on a machine you do not control, and you are trusting that it is not logged along the way. This page does it in your browser, so it never crosses the network. You can verify that: open your browser's network tab and generate — there are no requests.

Do you store or log the passwords?

No. The server only sends the page files; it has no endpoint that accepts a password and no database at all. Nothing is written to local storage either, so a reload gives you a fresh password with no trace of the previous one. There is no history feature for the same reason.

Is it really free, and where are the ads?

It is free with no catch: no sign-up, no paid tier, no ads and no tracking scripts. It is a small static page that costs practically nothing to run.

How long should a password be?

Twelve characters with all four sets ticked is about 77 bits of entropy and is a reasonable floor. For email, a password manager's master password, or anything holding money, use 16 or more. The how it works page has the full length-to-entropy table.

Should I include symbols?

Yes, where the site allows them. Symbols here exclude backslash, quotes, backtick, tilde and pipe, because those break often enough in shell commands, spreadsheets and connection strings to be more trouble than the small amount of strength they add. If a site rejects a symbol, untick the box and add two characters of length instead — that more than makes up for it.

Why are lookalike characters such as l, 1, O and 0 still included?

Removing them shrinks the alphabet and therefore the strength, and it only helps if you are reading the password aloud or retyping it by hand. These are meant to be copied and pasted into a password manager, so the full set is kept.

Should I use a different password for every account?

Yes, and that is the whole reason a generator is useful. When one site is breached, a reused password lets the attacker straight into every other account that shares it. Generate a separate password per site and keep them in a password manager — you are not meant to remember any of these.

Does the generator work offline?

Once the page has loaded, yes. Generating needs no network access, so you can disconnect and keep using it until you close the tab.

Generate a password or read how it works.