ANDROIDMIX

🔑 Password Generator

Create strong, random passwords with your browser's cryptographically secure generator — pick the length and character types and see the entropy. It all runs in your browser, so nothing is uploaded or stored.

🔑 Generate a Secure Password

What is a Password Generator?

A password generator builds a random string from the character types you select, giving you a login secret that's far harder to guess than anything you'd invent yourself. This one draws its randomness from your browser's cryptographically secure generator — never the predictable Math.random().

Everything runs on your device, so the password is never uploaded or stored and you can use the tool offline. Choose a length and mix of lowercase, uppercase, digits, and symbols, watch the entropy estimate, then save the result in a password manager. Length does most of the work.

❓ Frequently Asked Questions

How random are these passwords?

They use your browser's cryptographically secure random generator (window.crypto.getRandomValues), the same class of randomness used for security keys — not the weak, predictable Math.random(). Each character is drawn independently from the character set you choose, and each is exactly equally likely: a random byte that would favor some characters over others (256 does not divide evenly by 85 or 62) is thrown away and redrawn.

Is the password sent anywhere or saved?

No. Generation happens entirely in your browser and the password is never uploaded, logged, or stored. It runs locally, so you can even use it offline. For safe keeping, save the result in a password manager rather than a note. NIST notes that "Password managers have been shown to increase the likelihood that subscribers will choose stronger passwords, particularly if the password managers include password generators."

What length and character types should I choose?

Length matters most. NIST SP 800-63B (sec. 3.1.1.2) says services "SHALL require passwords that are used as a single-factor authentication mechanism to be a minimum of 15 characters in length", and it tells them not to demand character mixes. The default here is 16 characters. Add symbols only if the site accepts them: 16 characters from letters and digits (62) is 95.3 bits, from all four sets (85) is 102.6 bits.

What does the entropy figure mean?

It is length x log2(character set size): 16 characters from 62 is 16 x 5.954 = 95.3 bits, meaning 2^95.3 equally likely passwords. Each extra bit doubles the number an attacker must try. The figure is honest only for a password a computer picked at random, like this one; a password a person makes up has far less, whatever its length, because attackers try words, names, dates and common swaps first.