What this does
Generate random passwords up to 256 characters long. Choose lowercase, uppercase, digits, and symbols, edit the symbol set for sites that restrict it, exclude look-alike characters (I l 1 | O 0 o), and require at least one character from every selected set. Each result shows its entropy in bits.
Entropy, calculated exactly
Entropy is the base-2 logarithm of the number of passwords the generator could have produced. With "Require every selected set" on, the generator never outputs a password that misses a set, so the count is slightly smaller than pool^length. The figure shown accounts for that exactly using inclusion-exclusion, rather than overstating it. As a guide, 60 bits resists online guessing, 80 bits or more is strong, and 128 bits is out of reach of any attack.
How it is generated
Characters are chosen with crypto.getRandomValues and rejection sampling, so there is no modulo bias. When a set is required, one character from each set is placed first and the rest are drawn from the full pool, then everything is shuffled with an unbiased Fisher-Yates shuffle.
Tips
- Use a password manager and a unique password for every account. 20 characters is plenty for random passwords.
- For something you must type or remember, use the passphrase generator instead.
- Test any password with the strength checker to see how common patterns affect it.
Privacy
Passwords are created in your browser. They are never uploaded, logged, written to the URL, or stored, and they disappear when you close or reload the tab.