Secure Password Generator
Some sites demand at least two digits, others accept only a handful of symbols or forbid certain characters. This generator creates random passwords that meet the exact rules you set: length, minimum counts per character class, which symbols are allowed, characters to avoid, no repeated characters and a letter at the start. Every password comes from your browser’s cryptographic random generator.
- Runs in your browser
- No sign-up
- Free to use
Generated in your browser with its cryptographic random generator. Nothing is sent or stored; save the password in your password manager straight away.
How to use Secure Password Generator
- Set the length and how many passwords you want.
- Enter the minimum number of capitals, small letters, digits and symbols.
- List the symbols the site allows and any characters to avoid.
- Generate, copy one password into your password manager, and close the page.
Secure Password Generator features
Policy matching
Minimum counts per class, allowed symbols, excluded characters.
Cryptographic randomness
crypto.getRandomValues with rejection sampling; no Math.random.
Unbiased placement
Required characters are shuffled into random positions.
Readable options
Leave out look-alikes such as l, 1, O and 0.
Extra rules
No repeated neighbours, start with a letter.
Entropy shown
Bits per password from the effective character pool.
When to use Secure Password Generator
- Creating a password for a site with unusual rules.
- Generating several candidate passwords to choose from.
- Producing passwords for devices that accept only certain symbols.
- Setting temporary passwords for new user accounts.
Secure Password Generator FAQ
How is this different from the Password Generator?
The Password Generator makes good general-purpose passwords and passphrases. This one is for meeting a specific policy: minimum counts per character type, a restricted symbol set, forbidden characters and rules such as “must start with a letter”.
Are the passwords really random?
Yes. Each character comes from the Web Crypto random generator, with rejection sampling so that no character is more likely than another, and the result is shuffled with the same generator.
Are generated passwords stored or sent?
No. They exist only in this page until you close it. Nothing is sent to a server or saved in your browser.
Do minimum counts weaken the password?
Very slightly, because they rule out some combinations. With a reasonable length the effect is negligible.
Why leave out look-alike characters?
Characters such as l, 1, I, O and 0 are easily confused when a password must be read or typed from paper. Leaving them out costs a little entropy and prevents lock-outs.
What length should I use?
At least 16 characters wherever the site allows. Length adds more strength than extra symbol types.
When the rules get in the way
Password policies vary wildly. One site requires a symbol, another forbids most of them; one wants at least two digits, another caps the length at twenty. A general password generator often produces something a particular site rejects, and people respond by editing the password by hand, which makes it less random, or by reusing one that worked before.
This generator is built for those policies. You describe the rules, and it produces passwords that satisfy all of them. It places the required characters first, fills the remaining length from every allowed character, and then shuffles the whole password with cryptographic randomness so that the required characters do not sit in predictable positions.
The entropy shown is calculated from the effective pool of characters after exclusions. A 16-character password from about 80 characters carries roughly 100 bits, far beyond what any guessing attack can reach. If a site limits you to a short length or a small set of characters, the entropy figure tells you what that costs.
Random passwords are only practical with a password manager, which stores them and fills them in. Generate one, save it there immediately, and close this page. Never reuse a generated password on a second site, and enable two-factor authentication where available.