FreeGenDoc

Password

Free Password Generator

Generate a strong password using your browser’s cryptographic random number generator. Adjust the length and character sets, and watch the entropy update. The password is created on your device and never sent anywhere.

Your password

Strength

Excellent

Entropy
129 bits
Character pool
86 characters
Time to crack
10^19 years
20
664

This password is generated on your device with crypto.getRandomValues and is never transmitted, logged or stored. Reloading the page discards it.

What makes a password strong

Strength comes from unpredictability, not from cleverness. A password is only as good as the number of guesses an attacker would have to make, which is why length beats complicated substitution rules. Replacing an "a" with "@" adds almost nothing, because every cracking tool tries that automatically.

  • Length first. Going from 12 to 20 characters matters far more than adding another symbol.
  • Never reuse a password across sites. Reuse is what turns one company’s breach into your problem everywhere else.
  • Use a password manager. It is the only realistic way to have a different long password for every account.
  • Turn on two-factor authentication where it is offered. It protects you even if the password does leak.

Is this password generator safe to use?

The password is generated entirely in your browser using crypto.getRandomValues, the platform’s cryptographically secure random number generator. It is never sent to a server, never written to storage and never logged — there is no server-side code involved at all. That said, the most secure password is one you generate inside your password manager, which never displays it on a screen. If you are protecting something critical, prefer that.

Why not use Math.random?

Many free password tools use Math.random, which is not cryptographically secure. Its output is generated from an internal state that an attacker who observes enough values can reconstruct, which makes future and past outputs predictable. This tool uses crypto.getRandomValues instead, and maps random values onto the character set using rejection sampling so that every character is equally likely — a naive modulo would make some characters slightly more common than others.

What does entropy in bits mean?

Entropy measures how many guesses an attacker needs on average. Each bit doubles that number, so 60 bits is roughly a billion times harder than 30 bits. Under 50 bits is weak against a determined attacker, 75 bits is comfortable for most accounts, and above 100 bits is beyond brute force with any foreseeable hardware. The time-to-crack figure shown above assumes an offline attacker making 100 billion guesses per second against a fast hash; a site storing passwords properly with bcrypt or Argon2 would be far slower to attack, so treat that number as the pessimistic case. Note that requiring at least one character from each selected set very slightly reduces the theoretical maximum entropy, which the figure above does not subtract.

Should I change my passwords regularly?

No, not on a schedule. Forced rotation is outdated advice — NIST dropped it from its guidance because it pushes people toward predictable variations like Summer2024 becoming Summer2025. Change a password when you have a reason: a breach notification, a shared password, or any suspicion that it leaked. Otherwise a long unique password is better left alone.