Password Generator: Strong Random Passwords in 2026 (No Data Leaves Your Browser)
Reviewed · Updated
Quick answer: This free password generator makes random passwords of 8 to 64 characters, or passphrases of 4 to 10 words, inside your browser. Nothing is sent or saved. NIST's guidelines (SP 800-63B, revision 4, published 08/26/2025) tell sites to require at least 15 characters when a password is the only thing protecting a login.
This generator needs JavaScript, and it's off in your browser. Nothing is lost: the rules below make a strong password by hand, and your password manager's built-in generator follows the same idea.
| Rule | Example of the shape |
|---|---|
| Random password, 16+ characters, all four character types | v7#Rq2!mX9@kTz4w |
| Passphrase of 6 random words (roll dice for each word on the EFF word list) | cradle-oyster-tidy-glacier-pump-ninth |
| One password per account, never reused | — |
| Don't build it from names, dates or words about you | — |
Don't copy the examples above. They're published on this page, so they're no longer secret.
Made in your browser with crypto.getRandomValues. Nothing is sent, saved or logged.
What makes a password strong
Length does more than complexity. NIST’s Digital Identity Guidelines, SP 800-63B revision 4 (published 08/26/2025, read on 10/09/2026) set these rules for the sites that check your password:
- At least 15 characters when the password is the only login factor, and at least 8 when it’s one part of two-factor login.
- Sites should accept passwords of at least 64 characters.
- Sites shall not force composition rules such as “one uppercase, one number, one symbol.”
- Sites shall compare new passwords against a blocklist of common, expected and breached passwords.
The reason is math. Every random character from this generator’s full set (87 characters) adds about 6.4 bits; every word from a 7,776-word list adds about 12.9 bits. Each extra bit doubles the number of guesses an attacker needs. What the meter under the generator shows:
| Setting | Bits of randomness |
|---|---|
| 12 characters, all four types | about 77 |
| 16 characters, all four types | about 103 |
| 20 characters, all four types (default) | about 128 |
| 5-word passphrase | about 64 |
| 6-word passphrase | about 77 |
Randomness only counts if the password is new. A 20-character password reused on two sites is as weak as the weaker site’s security. One password per account is the rule that matters most.
Where to keep the passwords you generate
Nobody remembers fifty random 20-character passwords. A password manager stores them, fills them in, and makes new ones on its own. Two options with a public price, free plan first. I checked both pricing pages on 10/09/2026; we haven’t run our full review of either yet.
Proton Pass has a free plan with unlimited logins, notes and cards on unlimited devices, plus 10 hide-my-email aliases. Pass Plus is $2.99 a month, billed $35.88 for 12 months (the page shows $4.99 as the regular monthly price), with a 30-day money-back guarantee.
Save it in Proton PassAffiliate link · how it works →
1Password has no free plan, only a 14-day trial. The Individual plan is $2.99 a month billed annually for the first 12 months, a discount for new customers who buy on 1password.com; the regular price on the same page is $3.99 a month. What we saw in the trial account is in our 1Password review.
Your browser’s built-in password manager is free and better than reusing passwords. A separate manager adds sharing, apps for every device and breach alerts.
How this generator works (and what it doesn’t send)
- Random source. Every character and word comes from
crypto.getRandomValues, the browser’s cryptographic random number generator, notMath.random. Picks are unbiased: values that would favor some characters are thrown away and drawn again. - Every type you tick appears. If a password comes out missing a type you selected, the whole password is redrawn rather than patched, so the result stays random.
- Look-alikes. “Skip look-alikes” drops I, l, 1, O, 0 and o, for passwords you’ll read off a screen. It costs a little randomness (81 characters instead of 87).
- Passphrases use the EFF Large Wordlist (7,776 words, CC BY 3.0 US), built into the page.
- Nothing leaves your browser. The generator makes no network requests, sets no cookies, and writes nothing to storage. To check it yourself, open your browser’s developer tools, go to the Network tab and click New: no requests appear. The page works offline once it has loaded.
- It isn’t a password checker. Don’t type your current passwords anywhere to “test” them, here or on any other site.
What we checked
- NIST SP 800-63B, revision 4 (published 08/26/2025), password requirements — read on 10/09/2026
- This generator in Chrome DevTools on 10/09/2026: no network requests while generating, no cookies or storage written; Proton Pass and 1Password pricing pages captured the same day (desk review, no accounts opened)
FAQ
Is this password generator safe?
It builds every password in your browser with crypto.getRandomValues, the random source browsers provide for security code. Nothing you generate is sent to us or anyone else, and nothing is saved: close the tab and it's gone. You can confirm this in your browser's developer tools on the Network tab: clicking New makes no requests.
Should I use a passphrase or a random password?
Use a passphrase for the few passwords you type from memory, such as your password manager's main password or your computer login. Six words from a 7,776-word list give about 77 bits of randomness. Use a random password of 16 or more characters for everything your password manager fills in for you.
How often should I change passwords?
Only when there's a reason. NIST's guidelines (SP 800-63B, revision 4, published 08/26/2025) tell services not to force periodic password changes, and to force a change when there's evidence a password was compromised. Change a password right away after a breach notice or if you reused it somewhere that leaked.