Password Generator

Generate secure random passwords with customizable length and character requirements.

By Konstantin Iakovlev · Updated September 2026 · Source: NIST SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management (August 2025)

Uppercase
Lowercase
Numbers
Symbols
Exclude Ambiguous (0Ol1I)

Generated Password

mh<AstEF.MxlRDfE

Strength

Very Strong

Entropy

103 bits

Security Analysis

StrengthVery Strong
Entropy103.4 bits
Character Pool88 chars
Crack Time (1T guesses/s)Centuries+

Use the Password Generator above to calculate your results. Enter your values and see instant results — all calculations run in your browser.

Disclaimer: This calculator is for informational purposes only. Results are estimates based on the information you provide and the assumptions described on this page.

How It Works

This Password Generator creates strong, unique passwords tailored to your needs, significantly enhancing your online security. A random password used for one account only limits the damage when any single site is breached.

Each character is drawn with your browser's cryptographically secure random number generator (crypto.getRandomValues) from the sets you switch on: 26 uppercase letters, 26 lowercase letters, 10 digits and 26 symbols, 88 characters in all. Excluding look-alike characters (0, 1, I, L, O, i, l, o) trims the pool to 80. Entropy is length × log2(pool size), so the default 16 characters from all 88 give 16 × 6.46 = 103.4 bits. The characters are drawn independently, so a short password may happen to contain no digit or no symbol even when those sets are on.

Avoid using easily guessable information like birthdays, pet names, or common dictionary words in your passwords. While longer passwords are generally more secure, remember to use a password manager to store them safely rather than writing them down or reusing them across multiple accounts. There is no need to change a strong, unique password on a schedule: NIST SP 800-63B-4 (August 2025) tells services not to force periodic changes and to require a new password only when there is evidence the old one was compromised.

Example: A Password for a Banking Account

  1. 1 You need a new password for your online banking account and set the length to 18 with uppercase, lowercase, numbers and symbols all switched on.
  2. 2 Pool: 26 + 26 + 10 + 26 = 88 characters. The generator draws 18 of them with crypto.getRandomValues; each draw is independent, so not every type is guaranteed to appear.
  3. 3 A result looks like 'Q#8tPz!wYk2$jF9xG@' (yours will differ). Entropy: 18 × log2(88) = 18 × 6.46 = 116.3 bits, rated Very Strong.
  4. 4 Crack time: 88^18 ≈ 1.0 × 10^35 combinations at the calculator's assumed 1 trillion guesses per second is about 1.0 × 10^23 seconds, roughly 3.2 × 10^15 years, which the calculator shows as 'Centuries+'. At 18 characters it also clears NIST's 15-character minimum for a password used on its own; keep it in a password manager and use it for this account only.

Frequently Asked Questions

How long should a secure password be?
NIST SP 800-63B-4 (August 2025) sets a minimum of 15 characters for a password that is the only sign-in factor, and 8 when it is used with multi-factor authentication. Each additional character multiplies the number of possible passwords by the pool size (88 here with all four sets on). A 16-character random password with mixed characters is essentially unbreakable by brute force.
Are password generators safe to use?
Client-side password generators (like this one that runs in your browser) are safe because the password never leaves your device. Avoid generators that send data to a server. Always use a password manager to store generated passwords.
What makes a password strong?
A strong password is long (16+ characters), random (not based on words or patterns), and drawn from a large character pool. Mixing uppercase, lowercase, numbers and symbols enlarges the pool, but NIST SP 800-63B-4 tells services not to require such mixes and to check new passwords against lists of common and compromised ones instead. Avoid personal information, dictionary words, and common substitutions like "p@ssw0rd."