Password Generator
Generate secure random passwords with customizable length and character sets. See password strength and entropy.
About this calculator
Password strength comes down to one measurable quantity: entropy, expressed in bits, which captures how many possible passwords an attacker would have to guess through before finding yours by brute force. This calculator computes entropy as log2(character-set size ^ password length) -- every additional character in the password multiplies the guessing space by the size of the character set you've enabled, so entropy grows with BOTH how long the password is and how many distinct character types (uppercase, lowercase, numbers, symbols) it can contain. Doubling the character-set size adds one full bit of entropy per character; adding one more character to the password length adds roughly log2(charset size) bits all at once, which is usually a bigger jump.
That's why NIST's own Digital Identity Guidelines (SP 800-63B, within the current SP 800-63-4 suite) require a 15-character minimum for single-factor passwords and explicitly forbid verifiers from imposing composition rules like mandatory symbol or mixed-case requirements -- length, not complexity, is what the federal standard treats as the real driver of guessing resistance: a 20-character password using only lowercase letters typically has more entropy than an 8-character password stuffed with every symbol type. This calculator labels results Weak, Moderate, Strong, or Very Strong based on standard entropy thresholds (20/40/60/80 bits) that line up with widely cited password-strength guidance.
Inputs
Results
Generated Password
={#+0R5:9lfD({e$
Strength
Very Strong
Figures current as of 2025. Source: NIST SP 800-63B, "Digital Identity Guidelines: Authentication and Authenticator Management" (within the SP 800-63-4 suite, effective Aug. 1, 2025), National Institute of Standards and Technology
How to Use This Calculator
- Set the Password Length — 16+ characters is recommended for strong security.
- Toggle Include Uppercase, Include Lowercase, Include Numbers, and Include Symbols to define your character set.
- The Generated Password field shows a random password matching your criteria.
- Check the Entropy value in bits — aim for 80+ bits for high-security passwords.
- Review the Strength rating (Weak, Moderate, Strong, Very Strong) and regenerate as needed by adjusting length or character types.
What each input means
- Password Length
- Length of password (4-128 characters)
- Include Uppercase
- Include A-Z in the character set.
- Include Lowercase
- Include a-z in the character set.
- Include Numbers
- Include 0-9 in the character set.
- Include Symbols
- Include symbol characters (!@#$%^&* etc.) in the character set.
How this is calculated
Formula
Random selection from character setWorked example, using the default values
- Identify Input Parameters4 parametersPassword Length = 16, Include Uppercase = 1, Include Lowercase = 1, Include Numbers = 1 = 5 input(s) provided
- Calculate Generated PasswordGenerated Password={#+0R5:9lfD({e$ = ={#+0R5:9lfD({e$
- Calculate StrengthStrengthVery Strong = Very Strong
- Calculate EntropyEntropy103.35090589819676 = 103.35090589819676
Figures and sources
- Password/passphrase length over composition-rule requirements (2025) — NIST SP 800-63B, "Digital Identity Guidelines: Authentication and Authenticator Management" (within the SP 800-63-4 suite, effective Aug. 1, 2025), National Institute of Standards and Technology
Engine last updated . Checked against 2 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.
Frequently Asked Questions
Why does password length matter more than adding symbols?
Entropy is calculated as log2(character-set size raised to the password length), so length is an EXPONENT in the underlying guessing-space calculation while character-set size is only the base. Adding one more character to the password multiplies the total number of possible passwords by the full character-set size, whereas expanding the character set (say, from letters-only to letters+symbols) only multiplies it by a smaller factor per character already in the password. In practice, a longer password with a smaller character set usually beats a shorter one with every character type enabled -- which is exactly why NIST SP 800-63B (the federal Digital Identity Guidelines, current within the SP 800-63-4 suite) sets a 15-character minimum for single-factor passwords and directs verifiers NOT to impose composition rules like required symbol or digit mixes.
What entropy is considered strong enough for an important account?
This calculator labels 80+ bits "Very Strong" and 60-79 bits "Strong," thresholds that line up with widely cited password-strength guidance. For a critical account (email, password manager, financial login), aiming for the Very Strong tier gives meaningful headroom against both current brute-force hardware and future improvements, since each additional ~3.3 bits of entropy roughly doubles the number of guesses required.
Is this password generator producing truly random, unpredictable output?
Yes -- it draws characters using the Web Crypto API's cryptographically secure random number generator (crypto.getRandomValues), with rejection sampling to avoid any bias toward particular characters, rather than the predictable Math.random() function JavaScript uses for things like animations or non-security randomness. That makes the output suitable to actually use as a real password, not just to demonstrate entropy concepts. As with any generator, still pair it with a dedicated password manager so you aren't reusing or manually retyping passwords, and prefer a hardware security key or passkey over any generated password for your most critical accounts where that option exists.
Why do the entropy and strength results change even for the same length and character types?
Because the actual password is generated fresh with random character selection every time the calculator runs, even though entropy and strength are deterministic functions of length and which character sets are enabled -- the entropy BITS figure and strength label stay identical across regenerations at the same settings, only the visible password string itself changes each time.
Related Calculators
The questions that sit next to this one — chosen by subject, including calculators filed under a different category.
Password Strength Calculator
Check how strong your password could be based on length and character types. See estimated time to crack.
Cryptography & SecurityPassword Entropy Calculator
Calculate password entropy, brute force time, and security strength. Measure password complexity and cryptographic strength.
Math & StatisticsRandom Number (seeded)
Deterministic pseudo-random integers from a seed (reproducible).
CybersecurityIncident Response Cost Calculator
Estimate total cybersecurity incident response costs including forensics, legal, notification, and recovery based on IBM breach report data.
CybersecurityCybersecurity Risk Assessment Calculator
Calculate annualized loss expectancy (ALE) using FAIR-based risk analysis with threat frequency, vulnerability, and control effectiveness.
More in Technology & Computing.