Strong password generator

Create a random, secure password in your browser. Choose the length and character types — nothing is ever sent to a server.

XqK.*UuVP)bbYi+#W}4D

Strong131 bits of entropy
20

Look-alike characters (0/O, 1/l/I) are left out.

Generated on your device with your browser's cryptographic random number generator (crypto.getRandomValues). The password is never transmitted, logged or stored.

What makes a password strong

Length beats complexity

Every extra character multiplies the number of guesses an attacker needs. Aim for at least 16; this generator defaults to 20 and goes to 64.

Real randomness

Passwords you invent follow patterns — a name, a year, a swapped letter. These come from your device's cryptographic random source, so there's no pattern to spot.

One password per site

Reusing a password means a single breach unlocks every account that shares it. A unique password per site keeps the damage to one.

Don't rely on memory

Nobody remembers dozens of random passwords, and trying leads to weak, reused ones. Keep them in a password manager instead.

Frequently asked questions

Is this password generator safe to use?
Yes. Passwords are generated entirely on your device using your browser's cryptographic random number generator (crypto.getRandomValues). Nothing is sent over the network, logged, or stored — you can disconnect from the internet and it still works.
How long should a password be?
At least 16 characters for anything that matters, and longer for accounts you can't afford to lose, such as your email. This generator defaults to 20 characters and supports up to 64. The strength meter shows how many bits of entropy your current settings produce.
Do you store the passwords I generate?
No. A generated password only leaves your device if you choose to save it into your Captain Password vault while signed in. Using this page alone stores nothing.
What makes a password strong?
Length, randomness and uniqueness. A long password drawn at random from a large character set has no pattern to guess, and using a different one for every site means one breach can't unlock your other accounts.

Somewhere to keep it

A strong password only helps if you don't have to remember it. Save it to your Captain Password vault and reach it from any device.

Open your vault