Skip to content

Password Generator

Create a strong random password or an easy-to-remember passphrase in one click.

Free Generated in your browser Never sent or stored
 
- Time to crack: -
Created on your device with the Web Crypto API. Passphrase words: EFF large wordlist (CC BY 3.0).

How to use the password generator

  1. Choose a typeRandom password for accounts saved in a password manager, passphrase for anything you type from memory, PIN for phones and cards.
  2. Set the lengthAim for 16+ characters or 5+ words. The meter turns green above 80 bits of entropy.
  3. Copy and save itClick Copy, paste it into the site, then store it in your password manager straight away.

What makes a password strong?

Length matters more than anything else.

Each extra character multiplies the number of guesses an attacker needs. Adding symbols helps, but far less than adding length.

The second rule is randomness. A password a human invents - a name, a date, a keyboard pattern - is cracked from wordlists in seconds, however complex it looks.

The third rule is uniqueness. Reusing one password lets a single data breach unlock all of your accounts.

How long would it take to crack?

The table assumes an offline attack at 100 billion guesses per second - a realistic speed for a GPU rig against a leaked, fast-hashed password database. Times show the average case.

Password typeEntropyAverage time to crack
6-digit PIN19.9 bitsInstantly
8 characters, lowercase only37.6 bits1 second
8 characters, all character types51.9 bits6 hours
12 characters, all character types77.9 bits447 centuries
4-word passphrase51.7 bits5.1 hours
5-word passphrase64.6 bits4.5 years
16 characters, all character types103.9 bitsLonger than the age of the universe
6-word passphrase77.5 bits350 centuries
20 characters, all character types129.8 bitsLonger than the age of the universe

Sites that store passwords with slow hashes like bcrypt or Argon2 make attacks thousands of times slower. You cannot know how a site stores yours, so plan for the worst case.

Random password or passphrase?

Use a random password for every account your password manager fills in for you. Nobody needs to remember it, so make it long.

Use a passphrase for the few secrets you must type yourself: the password manager master password, your computer login and your email.

Our passphrases pick words at random from the EFF list of 7,776 words. Each word adds 12.9 bits, so six words reach 77 bits while staying easy to remember.

Password security checklist

  • Use a different password for every account.
  • Store them in a reputable password manager.
  • Turn on two-factor authentication, ideally with an authenticator app or passkey.
  • Change a password only when a service reports a breach or you suspect exposure.
  • Never send passwords by email or chat.

Developers storing passwords can test hashing algorithms with our bcrypt and Argon2 hash generator. Teaching children about passwords? Try the kids password generator.

Is this password generator safe?

Yes. The page uses crypto.getRandomValues(), the browser's cryptographically secure random source, with rejection sampling so every character is equally likely.

The password is built in your browser and is never sent to ScanWith, written to logs or saved in cookies. Ads and analytics on this page cannot read it.

Frequently asked questions

Is it safe to use an online password generator?

It is safe when the password is created on your device and never sent anywhere. This generator uses your browser's cryptographic random number generator (crypto.getRandomValues) and makes no network request with the result. You can even load the page, go offline and keep generating.

How long should a password be?

Use at least 16 random characters, or a passphrase of 5 or more random words, for important accounts. Current NIST guidance (SP 800-63B) treats length as the most important factor and requires sites to accept passwords of at least 64 characters.

Is a passphrase better than a random password?

Both are strong when long enough. A random password packs more strength into fewer characters, which is ideal when a password manager types it for you. A passphrase is easier to remember and type, so use it for your password manager master password and device logins.

What does password entropy mean?

Entropy, measured in bits, tells you how many guesses an attacker would need. Every extra bit doubles the work. Below 40 bits is weak, 60 bits is reasonable for low-value accounts and 80 bits or more is strong against offline cracking.

Do you store or see the passwords I generate?

No. The password never leaves your browser, is not logged and is not sent to ScanWith or any third party. Close the tab and it is gone.

Should I change my passwords regularly?

Not on a schedule. NIST no longer recommends forced periodic changes because they lead to weaker, predictable passwords. Change a password when a service reports a breach, or when you suspect it was exposed.