Password Generator guide
How the XGM Password Generator creates random passwords in your browser, what entropy bits mean, which length to choose and how to store passwords safely.
Why generated passwords are better
People choose passwords in predictable ways: words, names, dates, keyboard patterns and small variations of the same password across sites. Attackers use exactly those patterns when they guess passwords from leaked databases, testing enormous numbers of candidates per second. A password drawn uniformly at random from a large set has no pattern to exploit.
The biggest risk for most accounts is not guessing but reuse. When one site leaks passwords, attackers try the same email and password on other services, known as credential stuffing. A unique random password for every account turns a leak at one site into a problem for one account only.
How to use the Password Generator
- Open the Password Generator.
- Choose the length (20 by default) and the character sets: lowercase, uppercase, digits and symbols.
- Tick "Avoid look-alikes" if the password will be read or typed by a person, to drop characters such as
I,l,1,O,0ando. - Choose how many passwords to generate and press Generate.
- Copy one into your password manager or the account's password field.
Generated locally
Understanding entropy bits
Entropy measures how many possibilities an attacker would have to try, expressed in bits: each bit doubles the number. A random password of length L drawn from a pool of N characters has L × log2(N) bits. The generator shows this value and a label for the first password in the batch.
| Settings | Pool size | Length | Entropy |
|---|---|---|---|
| Lowercase only | 26 | 12 | about 56 bits |
| Lowercase + uppercase + digits | 62 | 12 | about 71 bits |
| All four sets | 86 | 16 | about 103 bits |
| All four sets | 86 | 20 | about 128 bits |
| Digits only (a PIN) | 10 | 6 | about 20 bits |
| Entropy | Label |
|---|---|
| Under 40 bits | Weak |
| 40–59 bits | Fair |
| 60–79 bits | Strong |
| 80 bits and more | Very strong |
Length is the cheapest way to add strength: four more characters from all sets add about 26 bits.
These numbers apply only to truly random passwords. A human-chosen password of the same length has far less real entropy, because attackers try likely choices first. That is also why online strength meters that only count character types can be misleading.
Which length to choose
| Use | Suggestion |
|---|---|
| Accounts stored in a password manager | 20 or more characters, all sets |
| Passwords you must type on a TV or phone | 16 or more, avoid look-alikes, perhaps without symbols |
| Password manager master password | A long passphrase you can remember, plus multi-factor authentication |
| Wi-Fi keys | 20 or more characters without look-alikes |
| Service accounts and API secrets | 32 or more random characters, or random bytes encoded as hex or base64 |
The symbol set contains 24 common punctuation characters that most sites accept. Some systems reject particular symbols, such as quotes or backslashes, which is why the generator avoids them. If a site rejects a generated password, generate a new one without symbols and add a few characters of length instead.
If a site limits password length or characters, use the longest password it accepts and drop only the sets it rejects. NIST guidance for verifiers asks services to allow long passwords and all printable characters, but not every site follows it.
Storing and using passwords safely
- Use a password manager. It generates, stores and fills unique passwords, and warns about reuse.
- Turn on multi-factor authentication, preferably passkeys or an authenticator app, especially for email and admin accounts.
- Never reuse passwords, particularly the one for your email account, which can reset all others.
- Do not send passwords in chat or email. Use the password manager's sharing feature or a one-time secret link.
- Change a password when a service reports a breach, and check the account for changes.
For developers storing user passwords, the rules are different: never store the password itself or a fast hash of it. Use Argon2id, scrypt or bcrypt with a per-user salt, as explained in the hash guide. For generating API keys and tokens in code, use the platform's secure random generator, as in the example below.
# Python
python3 -c "import secrets; print(secrets.token_urlsafe(32))"
# Node.js
node -e "console.log(require('crypto').randomBytes(32).toString('base64url'))"
# OpenSSL
openssl rand -base64 32Keep generated application secrets out of source code and repositories such as git.example.com. Load them from environment variables or a secrets manager, and rotate them when people with access leave.
FAQ
Are generated passwords sent anywhere?
No. They are generated in your browser with a cryptographically secure random source and never leave the page.
How long should a password be?
For passwords stored in a password manager, 20 characters or more. Length adds more strength than adding symbol requirements.
What does Avoid look-alikes do?
It removes characters that are easy to confuse when reading, such as I, l, 1, O, 0 and o. The pool gets slightly smaller, so add a character or two to compensate.
Is a passphrase better than a random password?
For passwords you must remember, a long passphrase of random words is easier to type and can be very strong. For everything stored in a manager, random characters are simplest.
What entropy is enough?
Around 80 bits is very strong for typical accounts; generated passwords of 16 or more characters from all sets exceed that comfortably.
Why does every password contain each selected character type?
The generator includes at least one character from each selected set, so sites that require a digit or symbol accept the password.
Can I trust browser-based generators?
Use one that generates locally with the Web Crypto API and does not load third-party scripts on the page. You can also generate passwords offline with a password manager or the commands in this guide.
Should I change passwords regularly?
Current NIST guidance advises against forced periodic changes. Change a password when there is a reason, such as a breach or suspected compromise.
Why generate several passwords at once?
It lets you pick one that a site accepts or that is easier to type on a particular device, without regenerating. Every password in the batch is independent and equally strong.
What are passkeys?
Passkeys replace passwords with a key pair stored on your device or password manager. They cannot be phished or reused across sites, so use them wherever a service offers them.
Does a strong password make MFA unnecessary?
No. Phishing and malware can capture any password. Multi-factor authentication, ideally passkeys, protects against those.