Password Generator
Generate password randomly.
| Characters used | |
|---|---|
|
|
|
| Length |
Password
What Is a Password Generator?
Passwords you come up with yourself tend to include patterns you find easy to remember — a birthday, a pet's name, a familiar word followed by a digit — and those same patterns make them easier to guess. This tool instantly creates a password with no such pattern, built from the character types and length you choose. You can turn lowercase, uppercase, numbers, and symbols on or off individually, so you can match whatever character requirements a particular service enforces.
Generation happens entirely in your browser, and the result is never sent to any server. Security depends mainly on length, so choose 12 characters or more whenever the service allows it. Keep in mind that a truly random password isn't something you're meant to memorize — pair it with a password manager so you never have to.
How to Generate a Password
- Choose which character types to include Pick from lowercase, uppercase, numbers, and symbols. Some services don't accept symbols, so check the site's requirements first.
- Set the length A minimum of 12 characters is recommended. If a service caps the length, using the full allowed length is the safest choice.
- Generate and copy the result Press "Generate" to see a new password. If you don't like it, you can generate as many times as you want.
- Save it to a password manager The generated value isn't stored on this page. Copy it right away and save it to a password manager before you navigate away.
Tips for getting more out of it
- The longer the password, the more secure it is. A minimum of 12 characters is generally recommended.
- Combining uppercase letters, lowercase letters, digits, and symbols greatly increases resistance to brute-force attacks.
- Store generated passwords in a password manager (1Password, Bitwarden, etc.).
- Reusing the same password across multiple services puts all your accounts at risk if one is breached.
- NIST recommends prioritizing "not reusing strong passwords" over "mandatory periodic password changes".
When to Use a Password Generator
Signing up for a new service
Creating a fresh, unique password for every account is the most reliable way to avoid reuse. If you're saving it to a manager, there's no need to memorize it at all.
Responding to a breach notice
If a service you use reports a breach, you can regenerate not just that password but every other account where you reused the same one.
Issuing temporary passwords
Useful for handing out initial account credentials at work. Narrowing the character set can make the value easier to read aloud.
Meeting character-type requirements
Generate a password that satisfies rules like "must include at least one symbol" without the trial and error of coming up with one yourself.
Password-Related Terms
- Brute-force attack
- An attack that tries every possible combination one by one. Each additional character multiplies the number of attempts required, making longer passwords dramatically harder to crack.
- Dictionary attack
- An attack that tries common words or passwords already exposed in past breaches. Including any meaningful word makes a password far riskier.
- Character set
- The categories of characters available — lowercase, uppercase, numbers, and symbols. Enabling more categories increases the number of possibilities per character.
- Password reuse
- Using the same password across multiple services. It's the single riskiest habit, because a breach in one place immediately endangers every other account that shares it.
- Password manager
- Software that stores your passwords in encrypted form. It's what makes long, unmemorable random passwords practical to use every day.
- Credential stuffing
- An attack that takes username/password pairs leaked from one breach and tries them on other services. Never reusing passwords is the only reliable defense.
FAQ
Side Note — The Most-Hacked Passwords in the World
Every year, "most-used password" rankings show that 123456, "password", and "111111" dominate the top spots. The most common password found in the 2009 RockYou data breach (approximately 32 million accounts) was also "123456".
With modern high-performance GPUs (e.g., NVIDIA RTX 4090), an 8-character alphanumeric password can be cracked in minutes to hours. By contrast, a 12-character or longer random password mixing letters and symbols would take tens of thousands of years even with today's computers.
In 2017, NIST removed "mandatory periodic password changes" from its recommendations and revised its guidelines to prioritize not reusing strong passwords. The old rule of changing passwords every three months had paradoxically led people to choose weak passwords like "Summer2024!".