PIN generator
Random PINs of 3 to 12 digits, one or up to 100 at a time, with the most guessable patterns left out if you wish.
How many PINs there are
A PIN of n digits is one of 10n codes, from 000…0 to 999…9. Every extra digit multiplies the count by ten and adds 3.3 bits. Leaving out the weak patterns removes about a hundred codes whatever the length, so it matters little to the count but a great deal to what people really choose.
| Digits | All PINs | Weak | Left | Bits |
|---|---|---|---|---|
| 3 | 1,000 | 116 | 884 | 9.8 |
| 4 | 10,000 | 114 | 9,886 | 13.3 |
| 5 | 100,000 | 112 | 99,888 | 16.6 |
| 6 | 1,000,000 | 110 | 999,890 | 19.9 |
| 8 | 100,000,000 | 106 | 99,999,894 | 26.6 |
| 10 | 10,000,000,000 | 102 | 9,999,999,898 | 33.2 |
| 12 | 1,000,000,000,000 | 100 | 999,999,999,900 | 39.9 |
What counts as a weak PIN
The generator removes three kinds of code, and only these:
| Pattern | Rule | 4-digit examples | How many |
|---|---|---|---|
| Repeated pair | Every digit equals the one two places before it | 1212, 6969, 1010, and all single repeated digits such as 0000 and 7777 | 100 |
| Run up | Each digit is one more than the one before, without wrapping past 9 | 0123, 1234 … 6789 | 11 − n |
| Run down | Each digit is one less than the one before, without wrapping past 0 | 9876, 4321 … 3210 | 11 − n |
A repeated pair is fixed by its first two digits, so there are 10 × 10 = 100 of them at any length, and the 10 single-digit codes such as 4444 are among them. A run is fixed by its first digit and has to fit between 0 and 9, so there are 11 − n each way: 7 up and 7 down for four digits, none for 11 or 12 digits. No code is both a run and a repeated pair, so for four digits 100 + 7 + 7 = 114 codes are removed and 9,886 remain.
The list is short on purpose. Removing every code that looks like a date or a year would cut thousands of PINs and the count would shrink noticeably, while a code from a generator gives an attacker nothing to go on. Those codes are dangerous only when a person chooses them.
What 3.4 million real codes show
The best-known evidence on chosen PINs is Nick Berry’s analysis for DataGenetics, published in September 2012. He collected almost 3.4 million four-digit passwords from leaked password databases, as a stand-in for PINs, and counted how often each code appeared. Every one of the 10,000 codes occurred, but very unevenly:
| Rank | Code | Share of all codes | Removed here |
|---|---|---|---|
| 1 | 1234 | 10.713% | Yes, run up |
| 2 | 1111 | 6.016% | Yes, repeated digit |
| 3 | 0000 | 1.881% | Yes, repeated digit |
| 4 | 1212 | 1.197% | Yes, repeated pair |
| 5 | 7777 | 0.745% | Yes, repeated digit |
| 6 | 1004 | 0.616% | No |
| 7 | 2000 | 0.613% | No |
The top 20 codes in the study made up 26.83% of all four-digit passwords, against 0.2% if people chose at random. Sixteen of those twenty fall under the patterns removed here, and together they account for about 24.9% of the dataset. The other four were 1004, 2000, 1122 and 2001. The study also found every code from 1900 to 1999 in the most popular fifth of the list, which points to years of birth: never use a year, a date or any number linked to you.
The figures have limits. They come from four-digit website passwords, not bank cards or phones, the data are from 2012 or earlier, and the dataset was not published, so the numbers can’t be checked independently. The broad pattern, a few memorable codes taking a large share, is what matters here.
Guessing a random PIN
A PIN is short, so it depends on the device or service limiting wrong guesses. NIST SP 800-63B-4 (July 2025) allows no more than 10 consecutive failed attempts for a PIN that unlocks an authenticator. Against a random PIN from this generator, 10 guesses succeed with a chance of 10 in 9,886, about 0.1%, for four digits, and about 0.001% for six. Against the codes in the DataGenetics study, an attacker trying its ten most common codes would have matched about 23.3% of them.
Questions
Is a PIN without patterns less secure, because there are fewer possible PINs?
Very slightly in theory, much more secure in practice. Leaving out 114 of the 10,000 four-digit codes lowers the count to 9,886, a loss of less than 0.02 bits. But people pick those patterns so often that attackers try them first. In one study of 3.4 million four-digit codes, the patterns removed here made up at least a quarter of all of them.
Why does the generator still give PINs like 1122 or 1990?
Only the patterns defined on this page are removed. A random PIN that happens to look like a date or a pair of pairs is no easier to guess than any other, because an attacker can’t know it came from a generator. What matters is that you don’t choose such a code yourself, especially a year of birth or any date linked to you.
Should I use 4 or 6 digits?
Use 6 or more when the device or service allows it. NIST SP 800-63B-4 (July 2025) requires PINs that unlock an authenticator to be at least 4 characters and recommends at least 6, with no more than 10 wrong attempts allowed. With 10 attempts, the chance of guessing a random 4-digit PIN is about 0.1%, and a random 6-digit PIN about 0.001%.
Are the PINs sent or saved anywhere?
No. They are made in your browser with its cryptographic random number generator, and nothing is sent or stored. The address bar keeps only your settings, so a shared link makes new PINs.
Can two PINs in a list be the same?
Yes. Each PIN is drawn independently, so in a list of 100 four-digit PINs at least one repeat turns up 39.5% of the time. If you are handing out codes that must all differ, check the list or use the random number generator with “No repeats”.