Password Generator
- 16
Making a PIN? The PIN generator makes 4- to 12-digit PINs and skips the codes people guess first, such as 1234.
Free Random Password Generator
Make a strong, random password in one click. Choose the length, from 6 to 256 characters, and which characters to use: uppercase and lowercase letters, numbers, and symbols. The default, 16 characters with all four, is strong for almost any account. Need one you can remember, like three random words? Use the passphrase generator.
Three things save time. Link to these settings turns your exact rules into a bookmark, so the next password is one click away. QR code moves the password to your phone without typing it. And once the page has loaded, it keeps working offline. It is free, with no sign-up.
Jump to: What is the password for? · If a website rejects it · Is it safe? · How strong is it?
What Is the Password For?
Pick what the password is for. The generator opens with the right settings, or the right tool opens for the job. The examples are made fresh with those settings each time the page loads.
- Website or app accountSaved and filled in by your password manager or browser, so you never type it. Strong enough for any account, and short enough for sites that cap the length.16 characters, the default
- Something memorableFor a password you have to remember and type, such as your computer login or the master password of your password manager.6 random words · Passphrase generator
- Typed by handFor a password you read on one screen and type on another. Letters and numbers only, without 1, I, i, L, l, 0, O, or o.16 characters · no look-alikes
- Wi-Fi networkFor a router or guest network. Easy to type on a TV, and guests can join by scanning a QR code.20 characters · Wi-Fi QR code generator
- A password you already haveSee how long it would take to crack, and whether it has shown up in a data breach.Password strength checker
- Phone or door codeA random PIN that skips the codes people guess first, such as 1234 and birth years.6 digits · PIN generator
- A new usernameA random online name that does not give away who you are.Username generator
- Server, terminal, or config fileLetters and numbers only, so it pastes into a terminal, .env file, or connection string without escaping.32 characters
- Temporary passwordsFor new accounts. Ask people to change them at first sign-in.16 passwords, 16 characters each · common symbols, no look-alikes
- A whole class or teamUp to 1,000 passwords, ready to import into Microsoft 365, Google Workspace, or Active Directory.Bulk password generator
To keep your own settings, bookmark the page or use Link to these settings. The link contains only the settings, never a password.
If a Website Rejects Your Password
Some websites limit the length of a password or the symbols they accept. Try these, in order:
- Use the maximum length the website allows, if it is shorter than your setting. Many websites stop at 16 or 20 characters.
- Use common symbols only: open the arrow beside $?% and choose Common symbols only. That keeps ! @ # $ % ^ & *, the symbols that most websites accept. If the website lists the symbols it allows, paste that list into Choose symbols.
- Turn symbols off. If the website allows it, add four characters: a random 20-character password with only letters and numbers is stronger than a 16-character password with symbols.
Why those eight? Apple publishes the password rules of hundreds of websites so that password managers can follow them. Of the 275 websites on that list that accept only certain symbols, this many accept each one:
The common eight are accepted almost everywhere; after them, support drops by half. And 29% of all the websites on the list allow no symbols at all, which is when Turn symbols off is the answer.
Is This Password Generator Safe?
It is built so that we never receive your password. The password is made in your browser, on your own device, by your device's secure random generator. There is no account and no password database.
You can check this yourself: once the page has loaded, turn off Wi-Fi or mobile data and keep generating. It still works, because making a password does not need the network.
No website can protect you from a device that is already infected, a harmful browser extension, or software that reads what you copy. Use a device and browser that you trust.
How Strong Is Strong Enough?
16 random characters with letters, numbers, and symbols is strong enough for any account, email and banking included. Longer does no harm if the website allows it, but you don’t need it. For the one password you type every day, such as your computer login or your password manager’s, a passphrase is easier to remember. Length matters most: each extra character multiplies the number of possible passwords.
On a website's sign-in page, guessing is slow, because the website stops attackers after a few tries. The harder case is a stolen password database, where an attacker can try 100 billion guesses a second. Here is how long one random password holds out as it grows, two characters at a time:
- k7#Rq!9v8 hours
- k7#Rq!9vT$8 years
- k7#Rq!9vT$2m75,000 years
- k7#Rq!9vT$2m@L660 million years
- k7#Rq!9vT$2m@Lx&5.9 trillion years
Fewer kinds of character make each one count for less. The average time to guess a random password, by length and kind:
| Length | All four types | Letters and numbers | Lowercase only | Numbers only |
|---|---|---|---|---|
| 8 | 8 hours | 18 minutes | 1 second | Instantly |
| 12 | 75,000 years | 500 years | 6 days | 5 seconds |
| 16 | Longer than the age of the universe | 8 billion years | 7,000 years | 14 hours |
| 20 | Longer than the age of the universe | Longer than the age of the universe | 3 billion years | 16 years |
A password that a person chooses is far weaker than its length suggests, because people use words, names, and dates that attackers try first. To test a password you already have, use the password strength checker. It also works in your browser.
Use It on Your Phone or Offline
Need the password on your phone? Choose QR code under the generator and scan it, instead of typing it. For a Wi-Fi network, add the network name, and guests can join by scanning the code.
Once PassGen.co has loaded in your browser, it can keep working without an internet connection, for example while you set up a new router. Try it once before you rely on it. Adding it to your home screen makes offline use more reliable, especially on iPhone.
On iPhone or iPad: open this page in Safari, tap the Share button, then tap Add to Home Screen.
On Android or a computer: open the browser menu and choose Install app or Add to Home screen.
Free. Adds the padlock icon to your home screen, and works offline.
- Tap the Share button in Safari. In newer versions of iOS, open the More menu (three dots) first.
- Tap Add to Home Screen.
- Tap Add. The padlock icon appears on your home screen and works offline.
You are using the installed app. It works offline, just like the website.
How It Works: Technical Details
For developers, IT teams, and anyone who wants to check our claims.
Show the technical details
- Secure randomness: every character comes from
crypto.getRandomValues(), the Web Crypto API, which uses your operating system's secure random source. It never usesMath.random(). - No modulo bias: each random choice uses rejection sampling, so every character in the chosen set has the same chance.
- Every selected type included: the password contains at least one character of each type you selected, and is then shuffled with the same secure source. This removes a small number of possible passwords, so the real strength is very slightly lower than the estimate shown.
- Strength estimate: bits = length × log2(number of characters in use); 16 characters from all four types is about 105 bits. Time to guess assumes the attacker knows your settings and tries half of all possible passwords, at 100 billion guesses a second: an aggressive offline attack on a database stored with a fast hash. Slow hashing, such as bcrypt or Argon2, makes it much slower.
- Symbols in commands and files: the symbols that websites accept most, such as $, #, !, and &, are the ones that have a special meaning in command shells, settings files, and connection strings. For those, turn symbols off and use more characters; the Server, terminal, or config file setting does this.
- Keys and tokens: use PassGen.co for text secrets that you choose yourself. Do not use it to replace API keys or tokens that a service issues, SSH keys, certificates, or keys that must be in a set format, such as hex, Base64, or a fixed number of bits.
Frequently Asked Questions
How long should a password be?
16 random characters for any account you save in a password manager or browser. Many websites cap the length at 16 or 20, so 16 also fits almost everywhere. NIST, a US standards agency, tells websites to require at least 15 characters when a password is used on its own, without a second step such as a code.
Is a 12-character password secure?
A random 12-character password with all four character types would take about 75,000 years to guess, even with a stolen database. That is fine for many accounts. But 16 characters is a better default, and it is no harder to use with a password manager.
Do I need symbols in my password?
No. Symbols help, but length helps more. If a website or device makes symbols difficult, turn them off and add a few characters instead.
What does each option do?
Length sets the number of characters, from 6 to 256. Several passwords makes up to 16, one per line. ABC, abc, 123, and $?% are uppercase letters, lowercase letters, numbers, and symbols: a ✓ means they are used. Click one to leave those characters out, and it is shown crossed out. 0Oo 1IiLl is off until you click it: then it leaves out those similar characters (0, O, o, 1, I, i, L, and l). The arrow beside $?% chooses which symbols to use: all of them, common symbols only (! @ # $ % ^ & *), or the ones you pick or paste from a website's list.
Does Google Chrome have a password generator?
Yes. Chrome, Safari, Edge, and most password managers suggest a strong password when you sign up for a website, and save it for you. That is a good choice for ordinary sign-ups. Use PassGen.co when the browser cannot help, such as for Wi-Fi or a device, or when you want to choose the length and characters yourself.
Can ChatGPT make a password for me?
It can write something that looks random, but it is not. A chatbot writes the characters it predicts are likely, so its passwords follow patterns that make them easier to guess than they look. The password also stays in your chat history. A generator like this one uses your device's secure random number generator, and the password never leaves your browser.
Can PassGen.co see or store my passwords?
No. The password is made by code that runs in your browser and is never sent to us. There is no account and no password database.
What is a good password for Wi-Fi?
20 random letters and numbers, with no characters that look alike, so it is easy to type on a TV. The Wi-Fi QR code generator makes one and prints a card, so guests can join by scanning.
Can I make several passwords at once?
Yes. Make up to 16 here, one per line. For a whole class or company, the bulk password generator makes up to 1,000 and exports CSV files ready to import into Microsoft 365, Google Workspace, or Active Directory.
How do I keep my passwords safe?
Save each one in a password manager, and use each password for one account only. When one website is breached, attackers try the same email address and password on other websites. Turn on two-step verification wherever it is offered.
How often should I change my passwords?
Only when there is a reason, such as a data breach at the service or signs that someone used your account. NIST tells websites not to force changes on a fixed schedule, because that leads people to choose weaker passwords.