EXP-009 · Tool · No signup

Password generator.

Crypto-random passwords, generated locally. Nothing leaves your browser. Pick a length, pick a pool, copy.

§ 01

Generate locally

009 / Password Generator

Output

Uses crypto.getRandomValues — not Math.random.

20

Strength

Entropy = length × log₂(pool). 80+ bits is strong.

pool size—
entropy—
verdict—
crack guess (10B/s)—

Minimum length is 8. “No repeats” caps length at pool size — pick a shorter password or a bigger pool. For vault-grade secrets use 20+ chars with all four pools.

§ 02

Use the tool

4 steps · 30 seconds

From slider to copied secret

The tool generates a password the moment the page loads, and re-generates on every control change. Follow these four steps to get a result matched to your threat model.

1 · Set the length. Drag the slider between 8 and 64 characters. Eight is the enforced minimum, but treat it as a floor for low-value logins only — the strength panel turns vault-grade around 20 characters with all four pools on. Longer is always better; there is no downside except typing.

2 · Pick the character pools. The four checkboxes — lowercase, uppercase, numbers, symbols — set the pool the password is drawn from. A bigger pool means more entropy per character. Leave all four on unless a site restricts you; the pool-size readout in the strength panel shows exactly what you selected.

3 · Set the readability rules. No lookalikes drops 0, O, 1, l, I and | so humans stop mistyping. No sequences rejects runs like abc or 321 (up to 200 retries, then it asks you to relax a rule). Guarantee mix forces at least one character from each enabled pool, which satisfies most sites' composition policies. No repeats caps each character at one use — handy for PIN-style codes, but it limits length to pool size.

4 · Read the strength panel, then copy. Check entropy, the Weak / Fair / Strong / Vault-grade verdict, and the crack-time illustration before you commit. Hit Copy and paste straight into a password manager — never into chat, email, or a shared doc.

shipping length20 characters
shipping poolslower + upper + numbers + symbols
shipping rulesno lookalikes · no sequences · guarantee mix on
shipping exceptionno repeats off (caps length at pool size)
§ 03

Entropy reference

Math · defaults · standards

The formula

Entropy = length × log₂(pool size). Every extra character multiplies the search space; every extra pool symbol adds a fraction of a bit per character. The strength panel on this page computes it live from your exact settings — the table below lists the pool sizes this tool actually uses, counted from its source (verified Sep 2026).

PoolSizeWhat it contains
Lowercase26a–z
Uppercase26A–Z
Numbers100–9
Symbols26!@#$%^&*()-_=+[]{}|;:,.<>?
All four combined88The shipping default pool
All four, no lookalikes82Drops 0 O 1 l I | for readability

Worked example 1 — the default. 20 characters × log₂(88) ≈ 129.2 bits. At an assumed 10 billion guesses per second that is on the order of 10²¹ years to exhaust — labeled on-page as an illustration, not a prediction. With no-lookalikes on (pool 82) it is 127.2 bits, still effectively uncrackable by brute force.

Worked example 2 — short and narrow. 12 lowercase-only characters: 12 × log₂(26) ≈ 56.4 bits, or roughly 55 days at 10 billion guesses per second (illustration). This is why the panel calls sub-50-bit outputs Weak and reserves Vault-grade for 90+ bits, with 80+ bits stated as strong.

These numbers follow NIST SP 800-63B §5.1.1: favor length over complexity, allow all printable ASCII characters, do not impose mandatory composition or rotation rules, and screen new secrets against lists of known-compromised passwords. This tool covers the first three — it never restricts your alphabet or forces rotation. It does not check breach lists, so run anything critical through Have I Been Pwned's password checker before relying on it. Randomness itself comes from crypto.getRandomValues, the browser's cryptographically secure source — never Math.random.

§ 04

Password FAQ

6 answers

Asked every week

Short answers to the questions this tool raises. Numbers below match the live calculator above (verified Sep 2026).

Is an 8-character password enough, or do I need 20+?

Eight characters is the tool's minimum, not a recommendation. An 8-character secret drawn from a broad 94-symbol alphabet holds about 52 bits of entropy — inside this tool's Fair band at best. Twenty characters from the default 88-symbol pool holds about 129 bits, which is Vault-grade. Use 8 only for throwaway logins, 16+ for anything tied to your identity or money, and 20+ for password-manager vaults, email accounts, and infrastructure secrets.

What does “no lookalikes” change?

It removes six confusable characters — 0, O, 1, l, I and | — shrinking the full pool from 88 to 82 symbols. A default-length password drops from about 129.2 to 127.2 bits, a loss of roughly 2 bits. That is a negligible security cost for a real usability gain whenever a human must read, dictate, or retype the secret. Keep it on unless a policy forces the full alphabet.

Why does “no repeats” sometimes refuse to generate?

With no repeats enabled, each character may appear at most once, so the password cannot be longer than the pool itself. Ask for a 30-character password from a 26-symbol pool and the math is impossible — the tool says so instead of silently weakening your rules. Fix it by shortening the password, enabling more pools, or allowing lookalikes back in. Leave the option off for normal passwords.

Passphrase or random string — which is better?

A random string packs more entropy per character; a 6–7 word diceware-style passphrase is far easier to memorize and can reach comparable strength (roughly 77–90 bits). Rule of thumb: random strings from this tool for anything a password manager stores, passphrases for the two or three secrets you must type from memory — the manager's master password and your device PIN. Never reuse either across sites.

Does this tool store or send my passwords?

No. Generation runs entirely in your browser using crypto.getRandomValues, and this page transmits nothing — there is no account, no analytics payload carrying your output, and no server to breach. Your password exists in the page's memory until you navigate away. Copy it directly into a password manager and clear your clipboard after pasting on a shared machine.

Why crypto.getRandomValues instead of Math.random?

Math.random is a fast, non-cryptographic generator whose output can be predictable — fine for shuffling demo data, unacceptable for secrets. crypto.getRandomValues draws from the operating system's secure entropy source, which is the documented requirement for key and password generation. This tool uses it exclusively; the only fallback is a plain random source on ancient browsers without Web Crypto, which you should treat as a warning to upgrade.

§ 05

Method & limits

Verified Sep 2026

How this page was checked

All figures above were re-derived from this page's own JavaScript in September 2026: pool strings counted character by character (26 / 26 / 10 / 26), entropy recomputed as length × log₂(pool), and the shipping defaults confirmed (length 20, all four pools on, no-lookalikes, no-sequences and guarantee-mix on, no-repeats off). Everything runs client-side — your passwords never leave the browser, and there is nothing to sign up for or delete later. Crack-time figures assume 10 billion guesses per second and are illustrations of scale, not forecasts of any real attack. Two honest limits: the tool does not check passwords against breach corpora (see Have I Been Pwned above), and no generator can protect a secret you reuse, photograph, or paste into the wrong window.