How this password generator works
What the generator actually does, and how to read the strength meter.
Where the randomness comes from
The password is built in your browser by crypto.getRandomValues, the
operating system's cryptographic random source. Math.random is not used
anywhere — it is fast but predictable, and unfit for anything that protects an account.
The draw is also unbiased. Turning a random byte into a character with a plain remainder makes the earlier characters of the alphabet come up more often than the later ones, because 256 does not divide evenly by the alphabet size. Bytes that would skew the result are discarded and drawn again instead.
Every character set you tick is guaranteed to appear at least once — a purely random draw leaves a whole set out often enough that sites requiring a symbol would reject the result. The password is then shuffled, so those guaranteed characters do not sit at the front in checkbox order.
Nothing is sent or stored
Generation happens entirely in the tab. The server has no endpoint that accepts a password, no database, and no analytics script; it only sends the page files. Nothing is written to local storage either, so a reload gives you a fresh password with no trace of the previous one.
You do not have to take that on trust. Open your browser's network tab and generate a few passwords — there are no requests.
How long should a password be?
Strength here is measured as entropy, in bits — a count of how many guesses an attacker would need, not a checklist of "has a capital letter". Each extra bit doubles the work. With all four character sets ticked:
| Length | Entropy | Rating |
|---|---|---|
| 6 characters | 39 bits | Fair |
| 9 characters | 58 bits | Good |
| 12 characters | 77 bits | Strong |
| 16 characters | 103 bits | Strong |
| 24 characters | 155 bits | Strong |
Twelve characters is a sensible floor and is what the generator starts on. For an email account, a password manager's master password, or anything holding money, use 16 or more — you are pasting it, not typing it, so length costs you nothing.
The meter reads full at 72 bits, which is roughly where brute forcing stops being realistic on rented hardware. One caveat worth stating: because one character from each ticked set is guaranteed, the true entropy is a fraction of a bit below the figure above.
What the meter does not tell you
It scores the settings, not the string. A generated password contains no dictionary words or keyboard runs, so there is nothing for a pattern-based estimator to find. That also means the rating is meaningless for a password you thought up yourself — Summer2024! would score well here and fall in seconds to a real attack.
Generate a password or read the frequently asked questions.