Random passwords · UUID · random numbers

Generated with your browser cryptographic random source (crypto.getRandomValues). Nothing is uploaded and nothing is recorded.

Password generator

—

UUID v4

A 128-bit identifier, suitable for database keys and request tracing.
—

Random integers

Distinct random integers within a range.
Results appear here.

What makes a password strong

Password strength is essentially entropy — how many guesses an attacker would need. Entropy grows much faster with length than with character variety: adding two random characters typically multiplies the search space more than forcing a symbol does. That is why length is the first thing to increase.

The single biggest real-world risk is not a short password but a reused one. Credential stuffing attacks replay passwords leaked from one service against others, so a strong password that you use twice is weaker than a modest one used once. A password manager removes the trade-off by letting every site have its own long random string.

Generators matter because humans are bad at randomness. This tool uses crypto.getRandomValues, the cryptographic random source built into the browser, rather than Math.random, which is deterministic enough to be predicted in some conditions. Generation happens on your device and the results are never sent anywhere.

A note on the “guarantee one of each class” option: it satisfies composition rules that some sites still impose, but it slightly reduces entropy because it constrains the output. Enable it only when a site requires it.

Finally, if you need an identifier rather than a secret, use a UUID v4: 122 random bits, formatted as 36 characters, with no meaningful collision risk for practical volumes.

Frequently asked questions

Is the password generation secure?

It uses crypto.getRandomValues, the browser cryptographic random source, not Math.random. Passwords are generated on your device and never transmitted or stored.

How long should a password be?

Length matters more than character variety. 16 characters is a good default; 20 or more for anything important. A password manager lets you use long random strings without having to remember them.

Should I require symbols?

Requiring symbols makes passwords harder to type and only slightly harder to guess compared with adding two more characters of length. Length is the stronger lever; keep symbols if the service allows them.