Skip to content
UniKit

Password generator

Generate strong passwords with browser cryptography: custom length and character sets, look-alike character exclusion, batches, entropy, strength levels and crack-time estimates — plus readable passwords like tavuko-rimeda.

Runs in your browserEvery computation happens in your browser — your data never leaves this device.

Generation settings

Every password is generated locally — nothing is uploaded.

Mode
16
1

Charset: 62

Crack time assumes 10¹⁰ guesses per second.

Results

What this tool does

  • Create a password on the spot: browser cryptography picks the characters, and you control the length, the character sets and whether to generate a batch at once.
  • For passwords you have to read out or type by hand: exclude look-alikes like 0 O 1 l I | to avoid transcription errors, or switch to readable passwords shaped like tavuko-rimeda.
  • See how strong the result really is: every entry reports its entropy in bits, a strength rating and a crack-time estimate assuming 10¹⁰ guesses per second.
  • Hand the list to someone else or store it: copy all of them, or export a txt where each line carries the length, charset size, entropy and strength.

Example

Input

Mode: random password
Length: 16
Charsets: A-Z, a-z, 0-9
Count: 1

Output

Password: 3NRbfh5ZIK3JRxAJ
Charset size: 62
Entropy: 95.3 bits
Strength: very strong
Crack time: centuries

Characters come from crypto.getRandomValues, so every run differs. The charset size of 62 is 26 uppercase + 26 lowercase + 10 digits, and the entropy is 16 × log2(62) ≈ 95.3.

Frequently asked questions

What ranges are allowed for length and count?

Length 4–128, count 1–50 and 2–8 syllables for readable passwords. Anything outside that range raises an error such as "length must be between 4 and 128" rather than producing a partial result.

Can I combine "one character from each set" with look-alike exclusion?

Yes, but be aware of the order: one character per selected set is taken first, and exclusions then shrink the pool. If you select symbols and then exclude many of them, a short password may struggle to include every class, so keep the length at 8 or more when both options are on.

How are entropy and crack time estimated?

Entropy is length × log2(charset size) and cracking time assumes half the keyspace divided by 10¹⁰ guesses per second, bucketed into instant / seconds / minutes … centuries. It is a theoretical brute-force figure and does not model dictionary or keyboard-pattern attacks.

Is the generated password actually random?

The randomness comes from crypto.getRandomValues, which is cryptographically secure, and the shuffle is Fisher–Yates, so placing one required character per set first does not leave a positional bias.

Are the passwords stored or uploaded?

No. Generation, statistics and export all happen locally, the page makes no network requests and results disappear on refresh. Clipboard contents linger though, so clear it after pasting wherever you need the password.

Keywords:password generatorrandom passwordstrong passwordpassphraseentropy密码生成随机密码强密码密码强度可读密码

Related tools