Create strong passwords or passphrases with crypto.getRandomValues, optional ambiguous-character exclusion, a strength meter with entropy estimate, and one-click copy. Nothing leaves your browser.
Random bytes come from crypto.getRandomValues, never Math.random.
Entropy ≈ length × log2(charsetSize) for passwords; passphrase entropy uses the wordlist size.
Strength bands are heuristics for UX, not a guarantee against all attacks.
entropy_bits ≈ L · log2(|charset|)
A 16-character password from an 85-symbol set (upper, lower, digits, symbols) has about 102.6 bits of entropy.
A 5-word passphrase from the 7,776-word EFF list has about 64.6 bits; add words for more strength.
No. Generation and copy happen only in your browser.
Characters like O/0 and I/l/1 are easy to misread when typing from a screen.
The EFF large wordlist (7,776 words), licensed CC BY 3.0 US. Prefer a password manager for important accounts.
Never. Only crypto.getRandomValues.
Strength estimates are educational. Use a reputable password manager for important accounts.
Removes O, 0, I, l, 1, and similar lookalikes.
Generated value
≈ 101 bits · Very strong
Generated locally with crypto.getRandomValues. Nothing is sent to a server.