Menu

Password generator

Random passwords of any length from 8 to 128 characters, or passphrases of 3 to 10 words, with the strength of each worked out exactly.

Common choices:

    This 20-character password, with at least one of each of the 4 chosen types, is one of 3 × 10³⁹ equally likely passwords drawn from 94 characters.

    Made on your device with its cryptographic generator. Nothing is sent or stored.

    Strength
    Strength130.9 bits
    Characters to choose from94
    Draws kept (all types present)89.1%
    Average time to guess at 10¹⁰ a second4 × 10²¹ years

    How strength is measured

    A random password is as strong as the number of passwords the generator could have produced, provided each is equally likely. That number is usually written in bits: a password with b bits of entropy is one of 2b possibilities, and each extra bit doubles the work of guessing it.

    passwordbits = length × log₂(characters to choose from)16 from 94: 104.9

    phrasebits = words × log₂(7,776)6 words: 77.5

    timeaverage = 2bits ÷ 2 ÷ guesses per secondat 1010 a second

    The table gives the bits, and the average time to find the password at 10 billion guesses a second, for common lengths and character sets. All 94 means the printable keyboard characters: 26 capitals, 26 small letters, 10 digits and 32 symbols.

    LengthDigits (10)Small letters (26)Letters and digits (62)All 94
    826.6 bits
    under a second
    37.6 bits
    10 seconds
    47.6 bits
    3 hours
    52.4 bits
    4 days
    1239.9 bits
    50 seconds
    56.4 bits
    55 days
    71.5 bits
    5 thousand years
    78.7 bits
    754 thousand years
    1549.8 bits
    14 hours
    70.5 bits
    3 thousand years
    89.3 bits
    1 billion years
    98.3 bits
    626 billion years
    1653.2 bits
    6 days
    75.2 bits
    69 thousand years
    95.3 bits
    76 billion years
    104.9 bits
    6 × 10¹³ years
    2066.4 bits
    158 years
    94.0 bits
    32 billion years
    119.1 bits
    1 × 10¹⁸ years
    131.1 bits
    5 × 10²¹ years
    2479.7 bits
    2 million years
    112.8 bits
    1 × 10¹⁶ years
    142.9 bits
    2 × 10²⁵ years
    157.3 bits
    4 × 10²⁹ years

    These figures hold only for passwords chosen at random, as here. A password a person makes up, such as a word with a capital and a digit added, has far fewer real possibilities than its length suggests, because attackers try the common patterns first.

    Every chosen type, without bias

    When you tick several character types, many generators force one character from each type into fixed positions or swap characters in afterwards. Both make some passwords more likely than others. This generator draws the whole password from all the allowed characters, checks that every chosen type appears, and if one is missing throws the password away and draws a completely new one. Every password that contains each type stays exactly as likely as any other.

    The requirement removes a few possibilities, so the tool reports the exact strength rather than the simple formula. With all four types, the share of draws kept and the strength are:

    LengthDraws keptAverage drawsSimple formulaExact strength
    846.1%2.1752.4 bits51.3 bits
    1270.0%1.4378.7 bits78.1 bits
    1682.3%1.21104.9 bits104.6 bits
    2089.1%1.12131.1 bits130.9 bits

    The exact count comes from inclusion and exclusion: all 94L strings, minus those with no capitals, no small letters, no digits or no symbols, adding back those missing two types, and so on. Leaving out the ten look-alike characters shrinks the set to 84 and costs about 0.16 bits per character: 127.6 bits instead of 130.9 at 20 characters.

    Passphrases from the EFF word list

    A passphrase is a few words picked at random from a fixed list. Its strength comes from the size of the list, not from the words being obscure, so the list can be public. This tool uses the EFF large word list: 7,776 words, the number of results of five six-sided dice, chosen by Joseph Bonneau at the Electronic Frontier Foundation in 2016 to be familiar and easy to type. Each word adds log₂ 7,776 = 12.9 bits.

    WordsBitsAverage time to guessWith a digit added
    338.824 seconds43.7 bits, 12 minutes
    451.72 days57.0 bits, 85 days
    564.645 years70.3 bits, 2 thousand years
    677.5350 thousand years83.5 bits, 21 million years
    790.53 billion years96.6 bits, 191 billion years
    8103.42 × 10¹³ years109.7 bits, 2 × 10¹⁵ years
    10129.21 × 10²¹ years135.9 bits, 1 × 10²³ years

    The added digit is one of 10, placed at the end of one of the words chosen at random, so it adds log₂(10 × words) bits: 5.9 bits for six words. Capitals and the separator add nothing, because they are fixed by your settings rather than chosen at random. They are there to satisfy sites that insist on them. Four words in the list have a hyphen of their own (drop-down, felt-tip, t-shirt and yo-yo), so choose a space or full stop between words if you want every word boundary to be clear. The EFF recommends six words, 77.5 bits, for most uses.

    Word list: EFF Large Wordlist for Passphrases, Electronic Frontier Foundation, 2016, used unchanged under the Creative Commons Attribution 4.0 licence. Your browser downloads the whole list (about 110 KB) the first time you choose a passphrase and picks words from it on your device.

    What NIST’s 2025 guidance says

    NIST Special Publication 800-63B-4, finalised in July 2025, sets the password rules for US federal systems and is widely copied elsewhere. Its rules are written for the services that check passwords, but they show what a good password policy looks like:

    TopicSP 800-63B-4
    Minimum length15 characters for a password used on its own; 8 for a password used only as part of multi-factor authentication
    Maximum lengthServices should allow at least 64 characters
    CharactersShould accept all printing ASCII characters, the space and Unicode
    Composition rulesMust not require mixtures of character types
    Changing passwordsMust not force periodic changes; must force a change when there is evidence of compromise
    BlocklistMust check new passwords against a blocklist of commonly used, expected or compromised values, which may include passwords from breaches, dictionary words and words specific to the service
    Password managersMust allow password managers and autofill; should allow pasting
    Hints and security questionsMust not allow stored hints or prompt for security questions

    The guidance also tells services to limit failed login attempts to no more than 100 in a row, which makes guessing through the login page hopeless for any random password here. Strength matters most when a site’s stored password hashes are stolen and attacked offline.

    The guessing speed behind the times

    The times on this page assume an attacker who has stolen a database of password hashes and tests 10 billion (1010) guesses a second, and they are averages: on average the right password turns up halfway through the possibilities. The assumption stands for a well-equipped offline attack on a fast hash. Services that use a slow password hashing scheme with a high cost factor, as NIST requires, cut the rate by many orders of magnitude; a weak or unsalted hash and many computers working together raise it. Divide or multiply the times accordingly: at 1012 guesses a second each time is 100 times shorter.

    Questions

    Is a passphrase as strong as a password?

    It can be. Strength depends on how many equally likely choices the generator had, not on how the result looks. Six words from the EFF list give 77.5 bits, about the same as a 12-character password from all 94 keyboard characters (78.1 bits). The passphrase is longer to type but far easier to remember.

    Why does ticking more character types barely change the strength?

    Each character adds log₂ of the set size, so going from 62 letters and digits to 94 characters with symbols adds only about 0.6 bits per character. Adding length helps more. A 16-character password of letters and digits (95.2 bits) beats a 12-character one with symbols (78.1 bits).

    Are the passwords sent or saved anywhere?

    No. They are made in your browser with its cryptographic random number generator, and nothing is sent or stored. The address bar keeps your settings, not the passwords, so a shared link opens the same settings but makes new passwords. The word list for passphrases is downloaded as a whole file, so the site can’t tell which words you got.

    What does “Leave out look-alikes” remove?

    Ten characters that are easy to misread when a password is copied by hand: capital I, small l, the digit 1, capital O, the digit 0, small o, the vertical bar |, the backtick ` and the quote marks ' and ". The page shows the smaller character set and the lower strength that results.

    How long should a password be?

    For a password kept in a password manager, length costs nothing, so 20 characters or more is sensible where the site allows it. NIST SP 800-63B-4 (July 2025) tells services to require at least 15 characters for a password used on its own and at least 8 when it is one part of multi-factor login. For a password you must remember, a passphrase of 6 or more words is easier.

    A site rejects my password. What should I change?

    Some sites limit length or refuse certain symbols. Untick symbols and add four or five characters to make up the strength, or tick “Leave out look-alikes”, which also drops the quote marks and the vertical bar.