Password Generator

Generate random passwords or word passphrases in your browser.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Generate controls

20

Used for random passwords.

Leaves out characters such as I, l, 1, O and 0 that are easy to misread.

8

Each word comes from a built-in 256-word list and adds 8 bits. Use more words for accounts that matter.

3

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use Password Generator

  1. Choose Random password or Word passphrase.
  2. Set the length or word count, then tick the character sets.
  3. Choose how many to create and select Generate.
  4. Copy each value into your password manager.

Example: Password Generator

Create three 20-character passwords with the default settings.

You add
Type Random password, length 20, lowercase letters, uppercase letters and numbers ticked, Avoid look-alike characters ticked, how many 3.
You get
Three passwords of exactly 20 characters drawn from the 50 characters left after look-alike characters are removed. The panel reports an estimated strength near 112.9 bits and marks it an upper bound. The values differ on every run.

Options

Avoid look-alike characters
Leaves out I, l, 1, O, 0, B, 8, S, 5, Z and 2 so values are easier to read. The smaller pool lowers the strength figure for the same length.
Use at least one character from every selected set
Guarantees one lowercase letter, one uppercase letter and one digit. The tool refuses a length shorter than the number of selected sets.
Words in the passphrase
Each word comes from a built-in 256-word list and adds exactly 8 bits, so eight words is about 64 bits.
Add a two-digit number
Adds a suffix from 00 to 99, worth about 6.6 bits, for sites that insist on a digit.

Supported inputs and limits

Length runs from 8 to 128 characters, passphrases from 6 to 12 words, and up to 20 values at a time. Randomness comes from crypto.getRandomValues, never Math.random, and nothing is sent anywhere. The strength figure is entropy against a random guess; it does not know about reuse or breach lists, and it does not score a password you already have. Use a unique password per account and store it in a manager.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

How the strength figure is worked out

Entropy measures the size of the space the tool draws from, in bits: the base-2 logarithm of the number of possible outputs. For a password the tool multiplies length by the base-2 logarithm of the pool size: 20 characters from 50 is 20 times 5.64, or 112.9 bits, and each extra character adds about 5.6 bits. Each passphrase word adds exactly 8 bits, and the two-digit number adds 6.6. NIST SP 800-63B (2025 revision) recommends allowing long passwords and checking new passwords against blocklists of breached and common values. This generator makes random values with the browser's secure random function; it does not itself check any list.

NIST SP 800-63B (2025 revision), Digital Identity Guidelines

Questions about Password Generator

Is a long password better than a passphrase?

Twenty characters from the 50-character pool is 112.9 bits. An eight-word passphrase with the number is 70.6 bits but easier to type on a phone, so pick the one you will actually use.

What does the strength figure mean?

It is bits of entropy, worked out from length and pool size. Higher is better, and the figure is an upper bound when one character per set is guaranteed.

Why is a short password with several sets refused?

It cannot hold one character from each selected set, so the tool stops instead of quietly dropping a set.

Should I tick symbols?

Only if the site accepts them. Symbols enlarge the pool, but some sites reject them or handle them badly.

Project manager: Tony Hines · Content updated 25 September 2026 · Report a problem