Password generator
Uses crypto.getRandomValues β the same OS-level randomness browsers use for encryption keys β not Math.random, which is predictable. Your password never leaves the page.
Runs entirely in your browser. Nothing is uploaded or stored.
Longer is stronger: each extra character multiplies the guessing work. 16+ is a good default.
FAQ
Why not Math.random?
Because it's a predictable pseudo-random generator. Passwords made with it can be reconstructed from a few outputs. This page uses the cryptographic source instead.
Is it safe to generate a password on a website?
Only if the site runs locally β check by disconnecting your network after the page loads; this one keeps working. Nothing is logged or transmitted.
What makes a password strong?
Length first: every extra character multiplies the guessing work. 16 characters from upper, lower, digits and symbols is around 100 bits of entropy.