Entropy explained
Entropy, in bits, measures how hard a password is to guess: length × log₂(character set size). A 20-character password using upper, lower, digits and symbols (about 87 characters) has over 125 bits of entropy — far beyond what any attacker can brute-force. The generator shows the entropy and a rating.
| Entropy | Rating |
|---|---|
| Under 50 bits | Weak |
| 50–69 bits | Fair |
| 70–99 bits | Strong |
| 100+ bits | Excellent |
How the generator works
- Randomness comes from your browser's cryptographically secure
crypto.getRandomValues, notMath.random. - At least one character from each selected set is included, then the result is shuffled.
- Look-alike characters (O/0, l/1, I) are excluded to avoid typing mistakes.
- Passwords are never sent to our server.
Password tips
- Use a password manager to store a unique password for every site.
- Turn on two-factor authentication, preferably with an authenticator app or passkey.
- For a password you must memorise, use a passphrase of 5–6 random words.
- Change passwords immediately if a service reports a breach.
Developers storing passwords should hash them with bcrypt or Argon2 — see the Hash Generator for why plain hashes are not enough.
Frequently asked questions
How long should a password be?
At least 14 to 16 random characters. Longer is always stronger, and a password manager makes long passwords easy to use.
Are generated passwords stored anywhere?
No. They are created in your browser with secure randomness and never sent to our server.
Is a passphrase better than a random password?
A long random passphrase of 5 to 6 words is strong and easier to remember. For passwords stored in a manager, random characters are ideal.
Why are some characters missing?
Characters that look alike, such as O and 0 or l and 1, are excluded to prevent typing mistakes.

