Password Generator: Strong Random Passwords in 2026 (No Data Leaves Your Browser)

Reviewed · Updated

Daria Klochko

Daria Klochko

Founder and editor

I built Vetted Privacy to see what privacy services actually do, not what they promise. Found a mistake? Email me.

in

Quick answer: This free password generator makes random passwords of 8 to 64 characters, or passphrases of 4 to 10 words, inside your browser. Nothing is sent or saved. NIST's guidelines (SP 800-63B, revision 4, published 08/26/2025) tell sites to require at least 15 characters when a password is the only thing protecting a login.

This generator needs JavaScript, and it's off in your browser. Nothing is lost: the rules below make a strong password by hand, and your password manager's built-in generator follows the same idea.

RuleExample of the shape
Random password, 16+ characters, all four character typesv7#Rq2!mX9@kTz4w
Passphrase of 6 random words (roll dice for each word on the EFF word list)cradle-oyster-tidy-glacier-pump-ninth
One password per account, never reused—
Don't build it from names, dates or words about you—

Don't copy the examples above. They're published on this page, so they're no longer secret.

What makes a password strong

Length does more than complexity. NIST’s Digital Identity Guidelines, SP 800-63B revision 4 (published 08/26/2025, read on 10/09/2026) set these rules for the sites that check your password:

  • At least 15 characters when the password is the only login factor, and at least 8 when it’s one part of two-factor login.
  • Sites should accept passwords of at least 64 characters.
  • Sites shall not force composition rules such as “one uppercase, one number, one symbol.”
  • Sites shall compare new passwords against a blocklist of common, expected and breached passwords.

The reason is math. Every random character from this generator’s full set (87 characters) adds about 6.4 bits; every word from a 7,776-word list adds about 12.9 bits. Each extra bit doubles the number of guesses an attacker needs. What the meter under the generator shows:

SettingBits of randomness
12 characters, all four typesabout 77
16 characters, all four typesabout 103
20 characters, all four types (default)about 128
5-word passphraseabout 64
6-word passphraseabout 77

Randomness only counts if the password is new. A 20-character password reused on two sites is as weak as the weaker site’s security. One password per account is the rule that matters most.

Where to keep the passwords you generate

Nobody remembers fifty random 20-character passwords. A password manager stores them, fills them in, and makes new ones on its own. Two options with a public price, free plan first. I checked both pricing pages on 10/09/2026; we haven’t run our full review of either yet.

Proton Pass has a free plan with unlimited logins, notes and cards on unlimited devices, plus 10 hide-my-email aliases. Pass Plus is $2.99 a month, billed $35.88 for 12 months (the page shows $4.99 as the regular monthly price), with a 30-day money-back guarantee.

Save it in Proton PassAffiliate link · how it works →

1Password has no free plan, only a 14-day trial. The Individual plan is $2.99 a month billed annually for the first 12 months, a discount for new customers who buy on 1password.com; the regular price on the same page is $3.99 a month. What we saw in the trial account is in our 1Password review.

Save it in 1Password

Your browser’s built-in password manager is free and better than reusing passwords. A separate manager adds sharing, apps for every device and breach alerts.

How this generator works (and what it doesn’t send)

  • Random source. Every character and word comes from crypto.getRandomValues, the browser’s cryptographic random number generator, not Math.random. Picks are unbiased: values that would favor some characters are thrown away and drawn again.
  • Every type you tick appears. If a password comes out missing a type you selected, the whole password is redrawn rather than patched, so the result stays random.
  • Look-alikes. “Skip look-alikes” drops I, l, 1, O, 0 and o, for passwords you’ll read off a screen. It costs a little randomness (81 characters instead of 87).
  • Passphrases use the EFF Large Wordlist (7,776 words, CC BY 3.0 US), built into the page.
  • Nothing leaves your browser. The generator makes no network requests, sets no cookies, and writes nothing to storage. To check it yourself, open your browser’s developer tools, go to the Network tab and click New: no requests appear. The page works offline once it has loaded.
  • It isn’t a password checker. Don’t type your current passwords anywhere to “test” them, here or on any other site.

What we checked

  • NIST SP 800-63B, revision 4 (published 08/26/2025), password requirements — read on 10/09/2026
  • This generator in Chrome DevTools on 10/09/2026: no network requests while generating, no cookies or storage written; Proton Pass and 1Password pricing pages captured the same day (desk review, no accounts opened)

FAQ

Is this password generator safe?

It builds every password in your browser with crypto.getRandomValues, the random source browsers provide for security code. Nothing you generate is sent to us or anyone else, and nothing is saved: close the tab and it's gone. You can confirm this in your browser's developer tools on the Network tab: clicking New makes no requests.

Should I use a passphrase or a random password?

Use a passphrase for the few passwords you type from memory, such as your password manager's main password or your computer login. Six words from a 7,776-word list give about 77 bits of randomness. Use a random password of 16 or more characters for everything your password manager fills in for you.

How often should I change passwords?

Only when there's a reason. NIST's guidelines (SP 800-63B, revision 4, published 08/26/2025) tell services not to force periodic password changes, and to force a change when there's evidence a password was compromised. Change a password right away after a breach notice or if you reused it somewhere that leaked.