Free tool · No sign-up
Password & Key Generator
Generate passwords, passphrases, and API keys from the browser's cryptographic random source — not Math.random, which is predictable and has no business near a credential. Tune length and character sets, read the real entropy in bits, or build a memorable multi-word passphrase instead.
Options
Character sets
Generated password
- Entropy
- 129 bits
- Strength
- Overkill
- Pool
- 88 chars
Method & assumptions
- Every character and word is drawn from crypto.getRandomValues, never Math.random, which is predictable and unfit for a credential.
- Selection uses rejection sampling, so no character is more likely than another — the naive modulo trick quietly biases toward the low end of the alphabet.
- Entropy is the honest figure: log2(pool) per character, or log2(wordlist) per word. It measures the generator, not any site's meter.
- A passphrase trades a longer string for something you can actually type and remember; six words from this list clear a comfortable bar.
- Everything is generated in your browser. No credential is transmitted, stored, or logged.
Other tools
More on the bench
- 01
UUID Generator
v4 and v7, one or a thousand. - 02
Hash Generator
SHA-2, SHA-3, and SHAKE, from text or a file. - 03
Supabase Security Auditor
Point it at your project, find the holes. - 04
JWT Decoder
Paste a token, read what is inside. - 05
Secret & .env Scanner
Paste code or a .env, catch the leaked keys. - 06
Security Headers Scanner
Enter a URL, grade its headers. - 07
CORS Tester
See exactly what a URL allows cross-origin. - 08
Base64 Encode / Decode
Text or files, both directions.
Software engineering
We write the software
behind tools like these
Anyone who needs a credential with enough real randomness behind it to survive a guessing attack.
- Free diagnostics
- Same-day across most of the metro
- Named technicians
- No fix, no labour charge