Password Generator
Generate strong random passwords in your browser with an entropy estimate.
Related tools
- Hash GeneratorHash text or a file with MD5, SHA-1, SHA-2, SHA-3 or HMAC.
- UUID GeneratorGenerate UUID v1, v3, v4, v5, v7 and ULID identifiers and decode existing UUIDs.
- JWT DecoderDecode JWT header and claims, warn about the algorithm and header tricks that get tokens forged, sign new tokens, and verify HS, RS, PS and ES signatures in your browser.
About this tool
Password Generator draws every character with crypto.getRandomValues and rejection sampling, so no character is more likely than another, and it produces up to 50 passwords of 4 to 128 characters per run. You choose the sets - a-z, A-Z, 0-9 and the 24 symbols !@#$%^&*()-_=+[]{};:,.?/ - and each password contains at least one character from every set you selected before a Fisher-Yates shuffle mixes the positions. The entropy figure describes the generator, computed as length × log2(pool size); it is not a verdict on a password you already use and says nothing about whether a string has appeared in a breach. The tool does not score existing passwords, does not build passphrases from a word list and does not keep a history of what it produced.
Every password is produced in your browser by crypto.getRandomValues, drawn through a rejection-sampling helper so the modulo bias of a naive remainder is avoided. Nothing is sent to the XGM API, nothing is written into the URL - the length, the sets and the count are page state, not query parameters - and no password is saved to local storage, so a reload leaves nothing behind. Copy and export run locally; once you close the tab the only copy of a password is the one you pasted into your password manager.
How to use it
- Open the Password Generator tool.
- Paste or type the input you want to inspect.
- Read the result, which is computed in your browser; the input is not sent to XGM.
- Copy the output only after checking it looks correct.
- Use related XGM tools if you need a broader diagnostic view.
FAQ
How is the entropy number worked out?
It is the length multiplied by the base-2 logarithm of the pool size. With all four sets the pool is 26 + 26 + 10 + 24 = 86 characters, which is about 6.43 bits per character, so the default 20-character password shows roughly 128 bits. The labels follow that number: under 40 bits is “Weak”, under 60 “Fair”, under 80 “Strong” and 80 or more “Very strong”.
Does forcing one character from each set make the password weaker?
Strictly yes, by a fraction of a bit: the rule removes the outcomes that happen to contain no digit or no symbol, so the true entropy sits just below the displayed length × log2(pool). At 16 characters and above the difference is far too small to matter in practice. The rule exists so the password survives sites that demand at least one digit and one symbol.
What does “Avoid look-alikes” cost me?
It removes I, l, 1, O, 0 and o, which shrinks the pool from 86 to 80 characters. That costs about 0.1 bit per character - roughly two bits on a 20-character password - and is worth it whenever the password will be read aloud, typed from a printout or dictated to a colleague. Add one character to more than make the difference back.
Is it better to add symbols or to add length?
Length, almost always. Turning symbols on moves the pool from 62 to 86 characters, which adds about 0.47 bits per character, while four extra characters from the 62-character pool add about 24 bits. If a site rejects symbols, raise the length instead of trying to compensate with exotic substitutions.
I changed the length but the list still shows the old passwords.
The batch is generated when the page loads and each time you press Generate, so option changes apply to the next run rather than rewriting the list in place. Press Generate after adjusting length, sets or count. Copying a password that was produced under the old options is otherwise easy to do by accident.