How to generate a strong random password
A new account deserves a unique password, and humans are terrible at inventing random ones. Choose the length and character sets, and your browser's cryptographic random source draws a password whose strength is shown in bits — generated on your device and never sent anywhere.
Step by step
Open the password generator
Start the free generator — it runs entirely in the page.
Choose the character sets
Combine lowercase, uppercase, digits, and symbols; 20 characters from all four sets gives about 131 bits of entropy.
Exclude ambiguous characters if needed
Drop glyphs that are easily confused when read aloud or retyped — the entropy figure already reflects the smaller alphabet.
Generate
Random bytes come from crypto.getRandomValues with rejection sampling, so every character in your alphabet is equally likely — no modulo bias.
Copy it into your password manager
The password exists only in the page: save it somewhere safe, because a reload means it is gone for good.
Tips that save a second try
Entropy describes the generation process, not what happens afterwards — a high-entropy password reused across sites is no safer than a weak one.
Prefer length over exotic rules: entropy is log2(alphabet size) × length, so adding characters beats adding sets.
Generate a fresh password per account; the tool stores nothing, so each visit starts clean.
Common questions
Are the generated passwords ever sent anywhere or saved?
No. They are produced in the page and held only in the page — nothing is written to storage, sent to a server, or logged — which also means a password lost on reload cannot be recovered.
Why not just take a random byte modulo the alphabet size?
256 is not a whole multiple of most alphabet sizes, so a plain modulo would make the first few characters slightly more likely. The generator discards and redraws bytes in that tail, keeping every character equally probable.