How this calculator works
Passwords are built with your browser’s cryptographically secure random number generator (the Web Crypto API), the same kind of randomness used for encryption keys.
Each character is picked uniformly from the characters you allow, using a method that avoids any bias toward particular characters. At least one character from every type you choose is included, then the order is shuffled.
Strength is shown as entropy in bits: length × log₂ of the number of possible characters. Each extra bit doubles the number of guesses needed. A 20-character password from about 85 characters has around 128 bits.
Avoiding look-alike characters removes 0, O, 1, l, I and similar symbols, which helps when a password has to be read or typed by hand, at a small cost in strength.
Length matters more than complexity. Adding characters raises strength faster than adding symbol types.
Worked example
Choosing a length
- With letters, numbers and symbols (about 85 characters), each character adds about 6.4 bits.
- 12 characters ≈ 77 bits; 16 ≈ 102 bits; 20 ≈ 128 bits.
- For accounts protected by a password manager, 20 or more characters is easy and very strong.
Questions people ask
Is it safe to generate a password online?
With this tool the password is created in your own browser and never sent over the internet or stored. You can even disconnect from the internet after the page loads and it still works.
How long should a password be?
At least 16 characters for important accounts. Current guidance from security agencies favours length over forced complexity.
Should I change my passwords regularly?
Current NIST guidance recommends changing passwords when there is evidence of compromise, rather than on a fixed schedule. Use a unique password for every account.
What should I do with the password?
Save it in a password manager rather than a note or document, and turn on two-factor authentication wherever it is offered.
Sources
Last reviewed October 2, 2026