What the password generator does

The tool produces two kinds of values. Password mode builds a random string of 4–128 characters from lower-case letters, upper-case letters, digits and symbols. Passphrase mode picks random words from a word list and joins them with a separator, for example copper-lantern-meadow-pickle-orbit-velvet. You can create up to 50 values at once.

Every settings change recalculates the character pool and the entropy. Values generated earlier are removed so they never sit next to settings that no longer describe them; press “Generate” for new ones.

How to use

  • Choose password or passphrase mode.
  • For a password set the length and the character classes. Edit the symbol set to drop characters the target system rejects.
  • Exclude look-alike characters (I, l, 1, O, 0) if needed, and keep the “at least one from each class” option on.
  • For a passphrase choose the number of words, the list (English or Turkish) and the separator.
  • Press “Generate”, copy the value and store it in a password manager. Use “Clear clipboard” when you are done.

Randomness and modulo bias

Random values come only from crypto.getRandomValues; Math.random is never used, and without Web Crypto the tool refuses to generate. Reducing a 32-bit number modulo the pool size would make some characters very slightly more likely. The tool therefore discards numbers from the top range that is not a whole multiple of the pool size and draws again (rejection sampling), so every character has the same probability.

The “at least one from each class” option never patches characters into a password. A password that misses a class is thrown away and drawn again from scratch, so the result is uniform over all passwords that meet the rule.

How entropy is calculated

For a random password the entropy is length × log2(pool); for a passphrase it is words × log2(list size). Appending a digit adds log2(10) ≈ 3.3 bits, while capitalising words adds nothing because the rule is fixed. When every class is required, the tool also shows the exact value after removing the passwords that break the rule; the difference is usually a few tenths of a bit.

SettingPool / listEntropy
20 characters, 4 classes, default symbols89129.4 bits
12 characters, letters and digits6271.3 bits
6 English words2,59768.1 bits
6 Turkish words2,38567.3 bits

The labels are this tool's own thresholds, not a standard: below 45 bits is weak, 45–63 fair, 64–99 strong and 100 or more very strong. Entropy only describes randomly generated values; a password a person picks is not this strong even at the same length.

Passphrases and word lists

The English (2,597 words) and Turkish (2,385 words) lists were compiled for this site from general vocabulary; they are not copies of the published Diceware or EFF lists. Words have 3–8 letters and contain no proper names or offensive terms. Both lists are larger than 2,048 words, so each word adds a little more than 11 bits. With the option that turns Turkish letters into ASCII, words that collide, such as “çam” and “cam”, are merged; the list drops to 2,369 words and entropy uses that real count. Without a separator word boundaries become ambiguous, so the value shown is an upper bound.

Example and interpretation

With the default settings a 20-character password looks like k7#Rv}q2Xm!pT9w;Ld4e and carries about 129 bits. If you want something easier to type, an eight-word English passphrase gives about 91 bits. The samples on this page only show the format; always generate a fresh value for real use.

Limits and privacy

Values live only in the page's memory; they are never written to the share link, browser storage, the console or a server. Optionally, only the settings are added to the share link. The clipboard is the exception: a copied value can be read by other apps and may be kept by Windows clipboard history or a clipboard manager. The “Clear clipboard” button overwrites the current clipboard with empty text but cannot delete history entries. The tool does not check whether a password has appeared in a breach and does not replace two-factor authentication.

Frequently asked questions

Are generated passwords stored anywhere?

No. Passwords are generated in your browser and are not written to a server, the link or browser storage. They are gone from memory when you close the page.

How long should a password be?

A random 16-character password with four classes carries about 103 bits, which leaves a wide margin for most accounts. Using a different password for every account matters more.

Is a passphrase safer than a random password?

Strength depends on the number of words. Six words give about 68 bits and eight words about 91 bits. A passphrase is longer but easier to type and remember.

Does excluding look-alike characters weaken the password?

The pool shrinks by five characters; for 20 characters the entropy drops from about 129.5 to 127.8 bits. If you will read and type the value by hand, that small loss is usually acceptable.

Why might I remove some symbols?

Some systems reject or reinterpret characters such as quotes, backslashes or spaces. Delete them from the symbol set; the entropy is updated for the new pool.

Published: · Updated: