idpixo

Password Generator

Create a strong random password using your device's secure random number generator. Nothing is uploaded and nothing is stored — the password is created in your browser and never leaves it.

How a strong password is generated here

Randomness comes from the Web Crypto API, crypto.getRandomValues(). That is the same operating-system cryptographic random source browsers use for security, and it is not the predictable Math.random(). Each character is chosen with uniform sampling (a rejection step removes modulo bias), so every position is equally likely to be any allowed character.

Why length beats clever substitutions

Password strength grows with the number of possible combinations, estimated here in bits of entropy. Adding characters increases entropy linearly; adding a larger character set raises the per-character contribution on a logarithmic scale. In practice a long, random passphrase of random characters is far harder to guess than a short word with a few letters swapped for symbols. Aim for at least 12–16 random characters for accounts that matter.

Using it safely

Privacy matters in every other task too. If you are also preparing document photos, our image compressor and UK visitor visa document checklist run the same way — entirely on your device. For a scannable code instead, the QR code generator is likewise local; sizes and print specs live on the photo size chart, and the passport photo checker validates a finished photo without uploading it.

Frequently asked questions

Is the password sent to a server?
No. It is generated entirely in your browser using the Web Crypto API; nothing is transmitted, logged or stored.

Why not use Math.random()?
That function is not designed to be unpredictable. This generator uses crypto.getRandomValues(), whose output is suitable for security.

What does the entropy figure mean?
It estimates how many random bits went into the password: higher is stronger. Around 80 bits is strong and 128 bits or more is very strong for typical online use.

Should I avoid the look-alike characters?
Only if you have to read or type the password by hand. Excluding them removes a few characters from the pool and slightly lowers entropy, so prefer long passwords when readability is not an issue.

Can I reuse this password on another site?
No. A unique password per account is the point; reuse means one breach exposes many accounts, however strong the password is.