Strong password generator

Random, private, and generated in your browser — copy it, or share it once with a one-time link

Generated in your browser. This page is not allowed to make network requests, so nothing you generate can leave it.

How this generator works

Each character is drawn uniformly from the characters you allow, using crypto.getRandomValues — the operating system's cryptographically secure random source, the same one used for encryption keys. Values that would favour some characters over others are discarded and redrawn (rejection sampling), so every character is exactly as likely as every other. When you require several character types, the whole password is redrawn until each type appears, which keeps every acceptable result equally likely.

The page is served with a Content-Security-Policy that blocks all network requests. The password exists only in this tab: it is not sent, logged, or stored anywhere.

How long should a password be?

The strength of a random password is its entropy: length × log2(number of possible characters). With all four character types there are 90 possibilities per character, about 6.5 bits each. Anything above roughly 80 bits is beyond any realistic guessing attack.

LengthAll four typesLetters + digits
12~78 bits~71 bits
15~97 bits~89 bits
16~104 bits~95 bits
20~130 bits~119 bits
32~208 bits~190 bits

NIST's digital identity guidelines (SP 800-63B-4, 2025) require at least 15 characters for a password that is the only factor protecting an account, at least 8 when it is combined with another factor, and ask sites to accept at least 64. They also tell sites to stop forcing composition rules and periodic changes — length is what counts. For passwords kept in a password manager, 16 to 20 random characters is a comfortable default.

Which characters to include

  • Symbols are optional. They add about half a bit per character over letters and digits. If a site rejects them, turn them off and add two or three characters.
  • No look-alikes removes 0 O 1 l I | — worth it for anything read from paper, typed on a TV, or dictated. It costs a fraction of a bit per character.
  • The symbol set leaves out quotes, the backslash, and the backtick, which tend to break shell commands and configuration files.

After you generate it

Save it in a password manager and use it for one account only — reuse is how one breach becomes ten. If you need a password you can remember and type, such as a master password, use the passphrase generator instead. And if the password is for someone else, don't paste it into email or chat, where it stays readable for years: press Share it as a one-time link. The password is encrypted in your browser, the link works once, and it expires after 24 hours.

Frequently asked questions

Is this password generator safe to use?

Yes. Every character is drawn in your browser from crypto.getRandomValues, the operating system's cryptographically secure random source, with rejection sampling so no character is favoured. The page is served with a Content-Security-Policy that blocks every network request, so the password cannot be sent anywhere — not to OncePad and not to anyone else.

Does OncePad see or store the passwords I generate?

No. Nothing is generated on our server and nothing is uploaded. If you press "Share it as a one-time link", the password is handed to the share form in the same tab and encrypted there before anything is sent; the server only ever receives ciphertext it cannot read.

How many characters should a password be?

At least 15 for a password that is the only thing protecting an account — the minimum in NIST SP 800-63B-4 — and 16 to 20 random characters is a comfortable default. Length matters far more than symbols: each extra random character adds about 6.5 bits.

Do I need symbols?

No. A random 20-character password of letters and digits has about 119 bits of entropy, which is out of reach of any guessing attack. Include symbols when a site demands them; if a site rejects them, turn them off and add two or three characters instead.

Why not just use my password manager's generator?

You should, for passwords you keep. This page is for the moments you are not in the manager — or when the password has to reach someone else, which is what the one-time link is for.