🧰 ToolPocket

← All tools

Password generator

Uses crypto.getRandomValues β€” the same OS-level randomness browsers use for encryption keys β€” not Math.random, which is predictable. Your password never leaves the page.

Runs entirely in your browser. Nothing is uploaded or stored.

Longer is stronger: each extra character multiplies the guessing work. 16+ is a good default.

FAQ

Why not Math.random?

Because it's a predictable pseudo-random generator. Passwords made with it can be reconstructed from a few outputs. This page uses the cryptographic source instead.

Is it safe to generate a password on a website?

Only if the site runs locally β€” check by disconnecting your network after the page loads; this one keeps working. Nothing is logged or transmitted.

What makes a password strong?

Length first: every extra character multiplies the guessing work. 16 characters from upper, lower, digits and symbols is around 100 bits of entropy.

0