Password Generator
Generate secure random passwords, memorable passphrases or GUIDs. Everything is generated in your browser and never sent anywhere.
What makes a password strong
Length matters more than complexity. A 16-character random password is far harder to crack than an 8-character one with symbols, and a four-word passphrase is both strong and possible to type from memory. The generator uses your browserās cryptographic random number source, not a predictable function, so no two results are related.
Uniqueness matters as much as strength. Most account takeovers use a password stolen from one site and tried on another. A strong password reused on three services protects none of them properly.
Which type to use
Use a random password for anything a password manager will fill for you, which should be almost everything. Use a passphrase for the few passwords a person has to remember and type, such as the password manager itself, a laptop login or a Wi-Fi key. Use a GUID when a system needs a unique identifier rather than a secret.
Cyber Essentials accepts three approaches: MFA plus at least 8 characters, or 12 or more characters with no complexity rule, or 8 or more characters with a block list of common passwords. Forced expiry and complexity rules are no longer required and are discouraged.
Password Generator: common questions
Are the passwords generated here sent anywhere?
No. They are created by JavaScript in your browser using the Web Crypto API and never leave the page. We cannot see them and nothing is logged.
Is a passphrase as secure as a random password?
A four-word passphrase from a large word list is comparable to a 12 to 14 character random password and far easier to remember. For anything you type by hand it is the better choice. For anything a password manager fills, use the longer random option.
How often should passwords be changed?
Only when there is a reason: a suspected breach, a shared password, or someone leaving. Routine expiry leads to weaker, predictable passwords. The National Cyber Security Centre and the Cyber Essentials scheme both advise against forced periodic changes.
Should a business use a password manager?
Yes. It is the only practical way to give every member of staff a unique strong password for every system, to share credentials safely within a team, and to remove access when someone leaves. We deploy and manage Keeper for businesses of all sizes.
More free tools
Strong passwords are only half the job
A business password manager gives every member of staff unique passwords, shared vaults for teams and a way to revoke access when someone leaves. We deploy and manage Keeper for businesses of every size.
