PRIVATE BY DESIGN

One less thing
to worry about.

Strong by default.
Advanced when you need it.

A little randomness.
A lot of peace of mind.

Password generator

● LOCAL
YOUR NEW PASSWORD
Checking secure randomness…
Password length
Customize password

At least one character from each enabled group. Changes generate a new value immediately.

Generated entirely in your browser.
Nothing is sent to our server.

MORE WAYS TO GENERATEAdvanced lab OPTIONAL

Different formats, same local randomness. Your default password is already strong.

Understand this estimate

Entropy describes uncertainty in this generator’s output, assuming the settings and algorithm are known. Constrained passwords show a conservative lower bound on min-entropy, not a claim of uniform distribution. Strength labels are guidance, not a guarantee.

It does not measure malware, phishing, password reuse, a service’s storage practices or the safety of your clipboard. No “years to crack” promises.

SMALL TOOL. CLEAR PRINCIPLES.

Random by nature.
Private by design.

01 / LOCAL

Your browser does the work.

Web Crypto provides cryptographically secure randomness from your browser. Every password, word and byte is selected on your device. No accounts, cookies, tracking or generation requests.

02 / UNIQUE

A fresh password for every account.

Use a different password everywhere. The default 20-character password is made for a password manager, which can save and fill it for you. Longer values provide more possible combinations.

03 / PRACTICAL

Letters or words. Your choice.

Random passwords are compact and work well in a password manager. Passphrases trade length for easier typing. Choose six or more random words when you need to enter a secret by hand.

A few good questions.

Can anyone see my generated passwords?

This application never sends generated values to a server or stores a history. They remain in the page’s memory until replaced or closed. Your browser, extensions, device and clipboard still need to be trustworthy. Hosting providers may receive ordinary access logs when you load static files, but no generated secrets.

What makes the default password strong?

Twenty random characters, selected using Web Crypto from 74 ASCII characters: uppercase, lowercase, digits and !@#$%&*+-=?_. Each group appears at least once, and positions are securely shuffled. There are no spaces, quotes, slashes or backticks. A site can still have its own restrictions.

Does this work offline?

Yes, after the app finishes caching on your first online visit over HTTPS. You can install it using your browser’s app menu. The offline cache contains only the application’s static files and word list. Your passwords are never cached.

Do I need extra sources of randomness?

No. Normal generation always uses local Web Crypto. Manual, cosmic and quantum entropy experiments are outside this first release. No external randomness service is contacted. Statistical patterns alone cannot certify cryptographic unpredictability.

Where do the passphrase words come from?

The Electronic Frontier Foundation’s long word list, bundled with this app under CC BY 3.0 US. No third-party word-list request is made at runtime. Separators keep word boundaries unambiguous.