Password Generator
Make a strong random password or an easy-to-type passphrase in one click. It is created on your own device and never sent to us or anyone else.
- Uses your browser’s secure random generator
- Nothing is sent, saved or logged
- Passwords up to 64 characters, or memorable passphrases
Copied to your clipboard
Tick at least one type of character.
Made on this device. Never sent or stored.
Why You Can Trust It
A password is only as private as the place it was made. Here is exactly what this page does and does not do.
Made on your device
Every password is created by this page, inside your browser, using its built-in cryptographic random generator — the same one it uses to protect your banking connection. It never travels to our server.
Nothing is kept
We do not log, store or see anything the generator makes. The only thing remembered is your choice of settings, kept in your own browser so they are ready next time. Close the page and the password is gone.
Every choice equally likely
Each character and each word is picked with exactly equal odds, with no patterns or shortcuts. That is what makes the strength figure honest: it measures the real number of possibilities, not how complicated the result happens to look.
Password or Passphrase?
Both are strong when they are made at random. The right one depends on whether you ever have to type it yourself.
Random password
Something like k7#Qm2!vR9@xT4pZ is impossible to remember, and that is the point — it belongs in a password manager, which fills it in for you.
Best for: email, banking, shopping and every other account a password manager can fill in.
Passphrase
Six random words such as Otter-Lantern-Cobalt-Meadow-Tango-Sprout-42 are far easier to type on a phone or read out, and still very hard to guess.
Best for: the few you type from memory — your computer login, your password manager’s master password, the home Wi-Fi.
Making a Strong Password Count
A strong password is the start. These four habits are what actually keep accounts safe.
Never use it twice
When one website leaks its passwords, attackers try the same email and password on every other site straight away. One password per account stops a single breach becoming several. Our guide to what to do if your email is hacked shows how quickly that spreads.
Let a manager remember them
Nobody can remember fifty random passwords, and nobody should try. A password manager stores them, fills them in, and warns you about reuse. Our password manager guide compares the main options.
Switch on two-factor login
Even a perfect password can be stolen. A second step — a code from an app or a security key — stops a stolen password from being enough on its own. Here is how to set up two-factor authentication.
Only type it on the real site
The strongest password is useless if you type it into a fake login page. Check the address before signing in, and never follow a login link from an unexpected email. Our phishing guide shows what the fakes look like.
Frequently Asked Questions
What people ask about generating and using strong passwords.
It depends entirely on where the password is made. This one runs completely inside your browser: the page loads, and from then on every password is created on your own device using the same secure random generator your browser uses for encryption. Nothing is sent to our server or anyone else’s. You can even disconnect from the internet once the page has loaded and it will keep working.
For accounts kept in a password manager, 16 random characters or more — you never have to type them, so there is no reason to go shorter. Where a site sets a limit, use the maximum it allows. For a passphrase you type from memory, six words from this generator is a sensible minimum, and seven if it protects something important like your email or your password manager.
Untick Symbols and make the password a few characters longer to make up for it. Length adds more strength than symbols do: every extra character multiplies the number of possible passwords, while dropping symbols only shrinks each character’s choices slightly. The strength meter shows you when you are back where you started.
It can be, with enough words. Each word from this list adds about 10.4 bits of randomness, so six words give roughly 62 bits and seven give about 73 — the meter shows the real figure for whatever you choose. What matters is that the words are picked at random by the generator, not chosen by you: a phrase you invent yourself, however long, is far easier to guess.
From the number of possible passwords the generator could have produced with your settings, which is only a fair measure because every character and word really is picked at random. The time shown is the average for one powerful graphics card making 100 billion guesses a second against a leaked, weakly protected password list. A well-funded attacker with hundreds of graphics cards can go hundreds of times faster, which is why we suggest 16 characters or more for anything important. Guessing through a website’s login page is millions of times slower.
Start with the ones that matter most: your main email account, because it can reset everything else, then banking, then any password you have used on more than one site. If you are not sure whether an account has been caught up in a data breach, a breach-checking service such as Have I Been Pwned will tell you which of your email addresses have appeared in one.
Yes. We set up password managers for households and small businesses across Edinburgh and the Lothians, move existing passwords across safely, and switch on two-factor login for the accounts that need it. If you think an account has already been taken over, get in touch and we will help you lock it back down.