Password Generator Online — Secure Random Passwords

Generate strong random passwords with browser CSPRNG. Choose length, character sets, exclude ambiguous glyphs, and create up to 50 passwords at once — copy all or one line at a time. Nothing is uploaded.

Loading…
Password generator — developer notes
Create strong local passwords with crypto.getRandomValues. Control length, character classes, ambiguous exclusion, and bulk count (up to 50). Results appear in a numbered list with per-line copy.

How generation works

Pick length (8–128), enable at least one character set, optionally exclude ambiguous glyphs (0, O, o, I, l, 1), and choose a count up to 50. Click Generate to fill a numbered list. Copy all passwords at once from the toolbar, or copy a single line with the button beside each row. Symbols use a fixed set: !@#$%^&*()-_=+[]{}|;:,.<>? — documented here for predictability.

Options

Length (8–128)
Enter any length from 8 to 128, or use the slider beside the field. Longer passwords increase entropy; some systems cap length — pick what your target allows.
Character sets
Toggle lower, upper, digits, and symbols. At least one set must be on; otherwise generation fails with a clear error.
Exclude ambiguous
Removes 0, O, o, I, l, and 1 from the pool to reduce support and verbal-read errors.
Count (1–50)
Generate multiple passwords for fixtures without flooding the page. Enter a number or use the slider beside the field (1–50).

Examples

Default strong password

Settings

length=16, all sets, exclude ambiguous

Sample shape

16 mixed characters without 0OIl1

Digits only API key fragment

Settings

length=12, digits only, exclude off

Sample shape

12 decimal digits

Related utilities

Generate strong local passwords for fixtures. To hash a password with bcrypt (not for production auth scaffolding), use bcrypt-hash. Hub: developer utilities.

Password generator FAQ

Security and options

Is Math.random used?

No. Generation uses crypto.getRandomValues (CSPRNG) when available.

Are passwords stored or uploaded?

No. Values exist only in your browser session until you copy or clear them.

Why exclude ambiguous characters?

Glyphs like 0/O/o and 1/l/I are easy to confuse when reading aloud or from screenshots.

What symbols are included?

The fixed set is !@#$%^&*()-_=+[]{}|;:,.<>? — chosen for common keyboard coverage without spaces.

Can I copy a single password?

Yes. Each generated password has its own copy button in the numbered list, in addition to Copy all in the toolbar.

Developer utilities

Timestamps, UUID, ULID, Nanoid, cron, passwords, regex, slugify, number bases, case, text diff, and chmod — all client-side.

Explore other tool categories

Minify

Shrink code and assets for production — minify JavaScript, CSS, HTML, JSON and XML before gzip or CDN deploy.

Beautify

Make code readable with consistent indentation — beautify JavaScript, CSS, TypeScript, SCSS, LESS, Markdown, GraphQL, SQL, YAML and more in your browser.

Unminify

Expand minified or compressed code — unminify JavaScript, CSS, TypeScript, SCSS, LESS, SQL, YAML and other formats when debugging or reviewing.

Conversion

Transform data between JSON, YAML, XML and CSV locally — no server uploads.

CSS preprocessors

Compile SCSS or LESS to standard CSS in the browser — pair with beautify or minify for a full stylesheet workflow.

JSON Tools

Validate, format, diff and explore JSON payloads — complementary to minifiers and converters.

SVG Tools

Preview, optimize with SVGO, export Data URI, resize, beautify, convert to JSX and validate SVG — all in your browser.

DevOps & Infra

Terraform HCL format/validate/minify, Dockerfile format & lint, Docker Compose and .env validation.

CI/CD

GitHub Actions and GitLab CI — format YAML and check workflow/job structure in your browser.

Logs & observability

Line-oriented JSON/NDJSON and Nginx/Apache access logs — format, filter, validate, and CSV/TSV.

Kubernetes

Multi-doc manifests, structural validate, Ingress/Deployment starters, and Helm values formatting.

Networking / IP

CIDR, subnets, and IPv4/IPv6 helpers — in your browser.

Security & tokens

JWKS, X.509 certificates, and secrets scan — browser-local.

API & schemas

OpenAPI tools to format, validate, and lint your specs.

Encoding

Encode or decode Base64, URL components and HTML entities — client-side only.

Text & Markdown

Count words, build Markdown TOCs, and clean line lists — all in your browser.

Serialization

Serialize and deserialize PHP data structures beside JSON workflows.