Free Password Generator
A password generator creates passwords that are random, so they cannot be guessed from your name, birthday or habits. Choose a length and the character types, or switch to passphrase mode for easy-to-remember random words, and this free tool makes up to 20 at once with an entropy estimate for each. Passwords are never stored.

Password Generator
Generators and Converters
About this tool
Random passwords use the server's cryptographically secure random number generator, the same kind used for encryption keys, not a simple shuffle. Each character is picked independently, and the tool makes sure that every character type you ticked appears at least once so the password passes the usual site rules. Longer is stronger: each extra character multiplies the number of possible passwords, so 16 or more characters is a good default for important accounts.
Passphrase mode joins random words from a list of about 2,000 common English words, for example "river-lemon-orbit-candle". Four words give about 44 bits of entropy and six give about 66, which is strong and much easier to type on a phone or remember than a string of symbols. Choose the separator, capitalise the words or add a number if a site insists. The entropy figure shown is calculated from the list size, so it only counts the randomness we actually added.
Generating a password here is only half the job. Save it in a password manager straight away, use a different one for every account and turn on two-factor sign-in for email, banking and your website admin. A tool in a browser cannot make a weak habit safe, so never reuse a generated password on a second site, and do not send passwords in chat or email.
Frequently asked questions
Are the generated passwords really random?
Yes. They are created with PHP's random_int function, which draws from the operating system's cryptographically secure random source, not from a predictable sequence. Each character or word is chosen independently. The server does not store or log the passwords, and each request creates a fresh set.
How long should my password be?
Use at least 12 characters for ordinary accounts and 16 or more for email, banking, hosting and website admin accounts. With all four character types, 16 characters gives roughly 100 bits of entropy, well beyond what an attacker can search. Length matters more than adding one more symbol.
What is a passphrase and is it safe?
A passphrase is several random words joined together, such as "river-lemon-orbit-candle". It is safe when the words are chosen at random, not from a song or a quote. Five or six random words are long enough for most accounts and far easier to remember and type than random symbols.
What does "avoid look-alike characters" do?
It removes characters that are easy to confuse when read or typed by hand, namely I, l, 1, O, 0 and o. This helps when a password has to be read from a screen or paper, for example a Wi-Fi key. The set is slightly smaller, so add a character or two of length.
Should I use the generated password straight away?
Yes, but save it in a password manager first, and use it for one account only. Do not reuse it elsewhere, and do not send it through email or chat. For important accounts also enable two-factor sign-in so that a stolen password alone is not enough.
