Password Generator
Free online password generator. Generate secure random passwords. Your data stays on your device.
Embed this tool
Copy and paste the code below into your website to embed this tool for free. An attribution link to The Util Box is required.
<iframe src="https://www.theutilbox.org/embed/password-generator" width="600" height="500" frameborder="0" style="border: none; max-width: 100%;" title="Free Password Generator tool from The Util Box"></iframe> <!-- Free tool by The Util Box — https://www.theutilbox.org/tools/password-generator --> <a href="https://www.theutilbox.org/tools/password-generator">Password Generator by The Util Box</a>
Password Generator — Cryptographically Random Passwords
This password generator uses crypto.getRandomValues(), the
browser's cryptographically secure random number generator, to produce passwords. That distinction is the
entire point of the tool. A password is only as strong as the randomness behind it, and a generator built on
Math.random() produces sequences that are predictable to anyone who has observed
enough output. The Web Crypto API source is the same one used for TLS key material.
The default length is 16 characters, and you can adjust it. Passwords are generated entirely on your device. Nothing is transmitted, nothing is logged, and closing the tab discards the result — there is no server holding a copy of your password.
Choosing Your Character Sets
You can enable or disable four character classes, and the generator draws only from the classes you leave switched on:
Lowercase (a–z)
26 characters. Always enabled — a password needs some base alphabet to be memorable enough to type.
Uppercase (A–Z)
26 characters. Leaving this off measurably weakens a password against brute force.
Digits (0–9)
10 characters. A small set, but useful when a system enforces a "must contain a number" rule.
Symbols (!@#$…)
The largest single expansion per character, but often rejected by legacy systems and painful to type on some keyboards.
Turning classes off shrinks the pool the generator draws from, which shortens brute-force time far faster than the character count suggests. Dropping from all four sets to lowercase-and-digits only takes a 16-character password from roughly 95^16 combinations to 36^16 — a reduction of about 20 bits of entropy for the same length. The strength readout updates as you change these options, so you can see the cost before you commit to it.
Reading the Strength Estimate
The meter scores the generated password so you can sanity-check it before saving it. It is a heuristic based on character pool size and length — useful for catching an obviously weak configuration, and not a substitute for understanding where the real risk lies.
Length is what matters. Each extra character multiplies the number of guesses an attacker has to make, while each extra character class is worth a fraction of that. A 20-character lowercase password is stronger than a 12-character password full of symbols, because a password manager autofills the long one and humans retype the short one. If you have a choice, take more characters over more symbols.
Practical Advice Before You Generate
- Never reuse a password. This matters more than any complexity rule. One breach of a small site should not expose your email account, and password reuse guarantees that it will.
- Use a password manager. It generates and remembers unique passwords, which removes the typing problem that causes people to fall back on short, memorable passwords.
- Turn on two-factor authentication. A password leaked in a breach stops mattering if a second factor is required to log in.
- Give every account a different password. Even the throwaway accounts. Credential stuffing attacks try the same password across dozens of services automatically.
- Store recovery codes offline. When you enable 2FA you will be given a set of single-use codes. If they live in the same place as your password, they protect nothing.
- Check for exposure after a breach. Services that have been breached usually tell you — that is the moment to change the password, rather than trusting the service to have fixed it.
The Same Principle Applies to Everything Else
Cryptographically secure randomness is not specific to passwords. The same generator powers keys, tokens and identifiers throughout this toolkit:
- UUID Generator — v4 UUIDs for database keys and distributed systems where a sequential integer would leak volume.
- Random String Generator — tokens, test fixtures and non-password secrets.
- Random Number Generator — sampling and simulations rather than secrets.
- Nano ID Generator — short, URL-friendly unique identifiers for front-end code.
- Hash Generator — checksums and fingerprints, with a note on why hashing is not encryption.
For hashing, note that a general-purpose hash like MD5 or SHA-1 is a checksum, not a password-protection scheme. Storing passwords requires a deliberately slow, salted algorithm like bcrypt, scrypt or Argon2, implemented in your application's authentication layer rather than in a web page.