How to Create a Strong Random Password in Seconds
Passwords we invent ourselves tend to be predictable: a name plus a birth year, or a familiar word with a number on the end. Those patterns are exactly what guessing tools try first. A password generated at random from a mix of letters, numbers and symbols has no pattern to exploit. This generator creates that kind of password with the length and ingredients you choose, for a new email account, online banking, home Wi-Fi or a website control panel.
It uses the browser's built-in crypto.getRandomValues function, a randomness source designed for security purposes, rather than ordinary random functions. The password is created inside your page only and is never stored or sent anywhere.
How to use it
- Enter the number of characters in Password length. The default is 14, and the field allows 4 to 64.
- Pick the ingredients with the checkboxes: Symbols, Numbers and Uppercase. All three are on by default, and lowercase letters are always included.
- Click Generate password. The result appears in a monospaced font so similar characters are easier to tell apart.
- Select and copy it into your destination, ideally a password manager.
- If it does not suit you or a site's rules, click again for a completely new one.
What you control
- Length from 4 to 64 characters; each extra character makes guessing dramatically harder.
- Uppercase letters A to Z, which you can switch off for case-insensitive systems.
- Digits 0 to 9.
- Symbols ! @ # $ % ^ & * ( ) _ + - =, which you can switch off for systems that reject them.
- With everything enabled, characters are drawn from a pool of 76.
Practical examples
- A 16-character or longer password for your main email, the account other accounts are recovered through.
- A long Wi-Fi password without symbols, so it is easier to type on a TV or printer.
- A temporary password for a new employee to change at first login.
- A database or hosting panel password, where length and symbols together make sense.
Tips and notes
- The tool does not force every selected type into each password, especially at short lengths. If a site demands a digit or symbol and none appears, generate again.
- Use a different password for every account so one leak does not expose the rest.
- Store passwords in a trusted password manager rather than a text file or phone screenshot.
- Turn on two-factor authentication wherever possible; a strong password is one layer of defence, not the only one.
Prefer something memorable? Try the passphrase generator. To test a password you already use, open the password strength checker, and developers needing long random keys can use the random token generator.