Password Generator

Create strong random passwords on your own device, with control over length and character types and an entropy score for every setting.

Strength
Very strong
Entropy
129.4 bits
Character pool
89 charactersupper 26 + lower 26 + digits 10 + symbols 27
Possible passwords
8.8 × 10³⁸
Average time to crack
1.39 × 10²¹ yearsoffline attack at 10 billion guesses per second
Password (generated in your browser)••••••••••••••••••••129.4 bits of entropy · Very strong
  • Passwords are created on your device and never sent anywhere. Use a password manager to store them.

Show the work

  1. Pool size N = upper 26 + lower 26 + digits 10 + symbols 27 = 89 characters
  2. Entropy = L × log₂(N) = 20 × log₂(89) = 20 × 6.4757 = 129.51 bits
  3. Requiring every type rules out some strings, which removes 0.144 bits → 129.37 bits
  4. Each character is drawn with crypto.getRandomValues using rejection sampling, so every character in the pool is equally likely.

The strongest password is one nobody chose: a long string drawn at random from a large set of characters. This generator builds such passwords on your own device using the browser’s cryptographically secure random number generator, and it tells you exactly how strong each setting is, in bits of entropy and in estimated cracking time.

How to use the password generator

  1. Set the length. 16 to 24 characters is a good range for most accounts.
  2. Choose how many passwords to create, up to 20.
  3. Tick the character types to include: uppercase, lowercase, digits and symbols.
  4. Optionally avoid look-alike characters and require at least one of each selected type (many websites demand this).
  5. Press Generate passwords. Press it again for a fresh batch. Copy the one you want into a password manager.

Each batch comes with a strength readout for the settings used, so you can compare the effect of adding length or character types by changing one setting and generating again.

Password entropy formula

entropy (bits) = L × log₂(N)

L is the length and N the size of the character pool: 26 uppercase + 26 lowercase + 10 digits + 27 symbols = 89 here. Each character drawn uniformly from 89 symbols adds log₂ 89 ≈ 6.48 bits.

Requiring at least one character of each type removes the strings that miss a type, so the calculator subtracts that small amount using inclusion–exclusion. The average time to crack is half the search space divided by the attacker’s guessing speed:

average guesses = 2entropy − 1  ·  time = guesses ÷ guesses per second

Worked example

With the default settings — 20 characters, all four types, at least one of each:

  1. Pool size: 26 + 26 + 10 + 27 = 89 characters.
  2. Raw entropy: 20 × log₂ 89 = 20 × 6.4757 ≈ 129.51 bits.
  3. The one-of-each rule rules out about 9.5% of strings, which costs about 0.14 bits, leaving 129.37 bits — rated very strong.
  4. At 10 billion guesses per second, a rate a well-equipped attacker can reach against a fast, unsalted password hash, the average search takes about 1.4 × 10²¹ years.

How length and character sets compare

Password type Entropy Average crack time at 10¹⁰ guesses/s
8 lowercase letters 37.6 bits about 10 seconds
8 characters, all types 51.8 bits about 2.3 days
12 characters, all types 77.7 bits about 390,000 years
16 lowercase + digits 82.7 bits about 12.6 million years
16 characters, all types 103.6 bits about 2.5 × 10¹³ years
20 characters, all types 129.5 bits about 1.5 × 10²¹ years

Adding four characters gains more than switching on every character type. That is why current guidance favors length.

Password best practices

Use a password manager

Random passwords are impossible to memorize across dozens of accounts. A password manager stores them, fills them in, and lets you use a unique password everywhere, so one breached website cannot unlock the others.

Follow modern guidance

NIST’s Digital Identity Guidelines (SP 800-63B) put length ahead of composition rules, recommend screening new passwords against lists of known-breached ones, and advise against forced periodic changes. The current revision asks for at least 15 characters when a password is the only sign-in factor.

Turn on multi-factor authentication

Even a perfect password can be phished. An authenticator app or a hardware security key stops most account takeovers that a stolen password alone would allow.

Entropy assumes true randomness

These numbers apply only to passwords produced by a random generator like this one. Human-chosen passwords, even long ones with symbols, follow patterns that attackers’ dictionaries and rules exploit, so their real strength is far lower than the formula suggests.

For numeric codes, try the PIN generator; to check a password field’s length limit, use the character counter.

Frequently asked questions

Is this password generator safe to use?

Yes. Passwords are created in your browser with crypto.getRandomValues, the operating system's cryptographically secure random number generator, and they are never sent over the network or stored by CalcFluent. For extra caution, you can generate a password with your network disconnected.

How long should my password be?

For a randomly generated password, 16 characters using all four character types gives about 104 bits of entropy, far beyond any practical brute-force attack. Use 20 or more for master passwords and encryption keys. Length matters more than complexity.

What does entropy in bits mean?

Entropy measures how many equally likely passwords the generator could have produced. Each extra bit doubles the number of guesses an attacker needs. A 20-character password from an 89-symbol pool has about 129 bits of entropy, or roughly 10³⁸ possibilities.

Why avoid look-alike characters?

Characters such as I, l and 1, or O and 0, are easy to misread when typing a password from paper or another screen. Excluding them lowers entropy slightly per character, so add a character or two of length to compensate.

Do I need to change passwords regularly?

Current NIST guidance says no: forced periodic changes tend to produce weaker, predictable passwords. Change a password when there is evidence it has been exposed, and use a unique password for every account.

Last reviewed October 2026 by the CalcFluent editorial team. How we check our calculators.