toolready. Password Generator

Password Generator

Generate cryptographically strong passwords — configurable length and charset.

What this does

Draws a password of the length you choose from the character sets you tick, one character at a time, from the browser's cryptographic random source. The password is generated locally and never transmitted — once the page has loaded you can go offline and it keeps working.

How random are these passwords?

Every character comes from crypto.getRandomValues, not Math.random(). Picking an index inside the alphabet uses rejection sampling: a 32-bit value is drawn and discarded if it falls in the short tail that would not divide evenly, then reduced modulo the alphabet size. That extra step removes the modulo bias that makes the first few characters of an alphabet slightly more likely in naive generators.

What are the available character sets?

  • a–z and A–Z — 26 each, both on by default.
  • 0–9 — on by default.
  • Symbols — off by default. 27 characters: !@#$%^&*()-_=+[]{};:,.<>?/~. No space, no quotes or backslash, so the result survives shell arguments and CSV fields.

Untick everything and the tool refuses to generate rather than falling back to a default. Note also that nothing forces at least one character from each set — a 16-character draw can legitimately contain no digit. Reroll if a site's rules demand one.

What does the strength readout mean?

It is entropy in bits, computed as length × log2(alphabet size) — the number of guesses an attacker faces, expressed as a power of two. The default settings (lower, upper, digits, similar characters removed) give a 57-character alphabet, so 16 characters is about 93 bits:

16 × log2(57) = 16 × 5.83 = 93 bits  →  "Very strong"

The bands are: under 28 bits weak, 28–60 fair, 60–90 strong, 90 and above very strong. This measures the generator, not a password you typed yourself — it says nothing about reuse, and a leaked 93-bit password is just as leaked as a bad one.

How long should the password be?

The slider runs from 6 to 128 and starts at 16. Length is the cheap lever: each extra character adds the same ~5.8 bits regardless of which sets you enable, whereas turning on symbols only lifts the per-character value from 5.8 to 6.5 bits. If a site caps you at 12 characters, turn on symbols; if it does not, just make it longer.

Why is "exclude similar" on by default?

It strips 0 O 1 l I, the glyphs that get misread when a password is typed off a screen or dictated over a phone. The cost is tiny — about 0.12 bits per character against the default alphabet — and you can turn it off for anything that only ever gets pasted from a manager.

Can I generate several at once?

Set Count up to 100 and you get that many, one per line, in the output box — convenient for seeding a set of service accounts. Copy takes the whole block. For other kinds of secrets and identifiers, see UUID generator, hash generator for SHA digests, and Base64 encoder.