Guides
How this password generator works
A short, checkable description of what happens when you press the button.
The page asks your browser for secure random numbers (crypto.getRandomValues), picks each character without bias, shuffles the positions, and shows the result. Nothing is sent to a server and nothing is saved.
Secure randomness
The generator uses crypto.getRandomValues, the cryptographically secure random number generator built into modern browsers. It does not use Math.random, which is not designed for security.
No bias
A common mistake is to take a random number modulo the number of characters, which slightly favors the first characters. This generator rejects values that would cause that and draws again, so every character in the pool has exactly the same chance.
One of each selected type
When you select several character types, the generator places at least one character of each, fills the rest from the whole pool, and then shuffles the positions with an unbiased shuffle. This satisfies sites that require each type.
Passphrases
Passphrase words come from the EFF Large Wordlist, 7,776 words by the Electronic Frontier Foundation, available under CC BY 3.0. Each word is picked uniformly at random from the list.
What is not done
- The result is not sent to our servers, not written to the address bar, and not stored in your browser.
- Analytics, if you accept it, counts page visits only. It never receives what you generated or the options you set.
- You can verify this by opening the network tab of your browser's developer tools and generating a password.
Frequently asked questions
Can I check the code?
Yes. The generator is a small plain JavaScript file that runs in your browser, so you can read it with your browser's developer tools.