Skip to content

Password Generator guide

Tool guide. Updated .

How the XGM Password Generator creates random passwords in your browser, what entropy bits mean, which length to choose and how to store passwords safely.

Why generated passwords are better

People choose passwords in predictable ways: words, names, dates, keyboard patterns and small variations of the same password across sites. Attackers use exactly those patterns when they guess passwords from leaked databases, testing enormous numbers of candidates per second. A password drawn uniformly at random from a large set has no pattern to exploit.

The biggest risk for most accounts is not guessing but reuse. When one site leaks passwords, attackers try the same email and password on other services, known as credential stuffing. A unique random password for every account turns a leak at one site into a problem for one account only.

How the generator builds a passwordSelected character sets are combined, one character from each set is drawn, the rest are drawn from the combined pool with a secure random source, and the result is shuffled.Choose sets and lengtha–z, A–Z, 0–9, symbols; optionally withoutlook-alikesOne character from each setGuarantees every selected set appearsFill to the chosen lengthUniform draws from the combined pool(crypto.getRandomValues)ShuffleFisher-Yates shuffle, so the guaranteedcharacters are not in fixed placesEntropy estimatelength × log2(pool size), shown in bits
Selected character sets are combined, one character from each set is drawn, the rest are drawn from the combined pool with a secure random source, and the result is shuffled.

How to use the Password Generator

  1. Open the Password Generator.
  2. Choose the length (20 by default) and the character sets: lowercase, uppercase, digits and symbols.
  3. Tick "Avoid look-alikes" if the password will be read or typed by a person, to drop characters such as I, l, 1, O, 0 and o.
  4. Choose how many passwords to generate and press Generate.
  5. Copy one into your password manager or the account's password field.

Generated locally

Passwords are created in your browser with the Web Crypto random number generator. They are not sent to XGM, stored or put in the URL.

Understanding entropy bits

Entropy measures how many possibilities an attacker would have to try, expressed in bits: each bit doubles the number. A random password of length L drawn from a pool of N characters has L × log2(N) bits. The generator shows this value and a label for the first password in the batch.

Entropy for common settings
SettingsPool sizeLengthEntropy
Lowercase only2612about 56 bits
Lowercase + uppercase + digits6212about 71 bits
All four sets8616about 103 bits
All four sets8620about 128 bits
Digits only (a PIN)106about 20 bits
Labels shown by the generator
EntropyLabel
Under 40 bitsWeak
40–59 bitsFair
60–79 bitsStrong
80 bits and moreVery strong

Length is the cheapest way to add strength: four more characters from all sets add about 26 bits.

These numbers apply only to truly random passwords. A human-chosen password of the same length has far less real entropy, because attackers try likely choices first. That is also why online strength meters that only count character types can be misleading.

Which length to choose

Practical recommendations
UseSuggestion
Accounts stored in a password manager20 or more characters, all sets
Passwords you must type on a TV or phone16 or more, avoid look-alikes, perhaps without symbols
Password manager master passwordA long passphrase you can remember, plus multi-factor authentication
Wi-Fi keys20 or more characters without look-alikes
Service accounts and API secrets32 or more random characters, or random bytes encoded as hex or base64

The symbol set contains 24 common punctuation characters that most sites accept. Some systems reject particular symbols, such as quotes or backslashes, which is why the generator avoids them. If a site rejects a generated password, generate a new one without symbols and add a few characters of length instead.

If a site limits password length or characters, use the longest password it accepts and drop only the sets it rejects. NIST guidance for verifiers asks services to allow long passwords and all printable characters, but not every site follows it.

Storing and using passwords safely

  • Use a password manager. It generates, stores and fills unique passwords, and warns about reuse.
  • Turn on multi-factor authentication, preferably passkeys or an authenticator app, especially for email and admin accounts.
  • Never reuse passwords, particularly the one for your email account, which can reset all others.
  • Do not send passwords in chat or email. Use the password manager's sharing feature or a one-time secret link.
  • Change a password when a service reports a breach, and check the account for changes.

For developers storing user passwords, the rules are different: never store the password itself or a fast hash of it. Use Argon2id, scrypt or bcrypt with a per-user salt, as explained in the hash guide. For generating API keys and tokens in code, use the platform's secure random generator, as in the example below.

Generating secrets in code
# Python
python3 -c "import secrets; print(secrets.token_urlsafe(32))"

# Node.js
node -e "console.log(require('crypto').randomBytes(32).toString('base64url'))"

# OpenSSL
openssl rand -base64 32

Keep generated application secrets out of source code and repositories such as git.example.com. Load them from environment variables or a secrets manager, and rotate them when people with access leave.

FAQ

Are generated passwords sent anywhere?

No. They are generated in your browser with a cryptographically secure random source and never leave the page.

How long should a password be?

For passwords stored in a password manager, 20 characters or more. Length adds more strength than adding symbol requirements.

What does Avoid look-alikes do?

It removes characters that are easy to confuse when reading, such as I, l, 1, O, 0 and o. The pool gets slightly smaller, so add a character or two to compensate.

Is a passphrase better than a random password?

For passwords you must remember, a long passphrase of random words is easier to type and can be very strong. For everything stored in a manager, random characters are simplest.

What entropy is enough?

Around 80 bits is very strong for typical accounts; generated passwords of 16 or more characters from all sets exceed that comfortably.

Why does every password contain each selected character type?

The generator includes at least one character from each selected set, so sites that require a digit or symbol accept the password.

Can I trust browser-based generators?

Use one that generates locally with the Web Crypto API and does not load third-party scripts on the page. You can also generate passwords offline with a password manager or the commands in this guide.

Should I change passwords regularly?

Current NIST guidance advises against forced periodic changes. Change a password when there is a reason, such as a breach or suspected compromise.

Why generate several passwords at once?

It lets you pick one that a site accepts or that is easier to type on a particular device, without regenerating. Every password in the batch is independent and equally strong.

What are passkeys?

Passkeys replace passwords with a key pair stored on your device or password manager. They cannot be phished or reused across sites, so use them wherever a service offers them.

Does a strong password make MFA unnecessary?

No. Phishing and malware can capture any password. Multi-factor authentication, ideally passkeys, protects against those.

Sources