Free security tools

Generators that run entirely in your browser — and a one-time link for when the result has to reach someone

  • password generator — Generate a strong random password in your browser: 8 to 128 characters, letters, numbers, and symbols, no look-alikes. Nothing is sent or stored. Share it once with a one-time link.
  • passphrase generator — Generate a random passphrase from the EFF wordlist in your browser — 4 to 12 words, your choice of separator, about 10.3 bits per word. Easy to type, hard to guess, never sent.
  • API key generator — Generate a random API key, secret, or token in your browser: hex, base64url, or alphanumeric, 16 to 128 characters, optional prefix. 128+ bits by default; nothing leaves the page.
  • Wi-Fi password generator — Generate a strong Wi-Fi password that is still easy to type on a phone or TV: 8 to 63 characters, no look-alike characters. Made in your browser and never sent.

Why you can trust a web generator here

Each tool draws its randomness from crypto.getRandomValues, the browser's cryptographically secure generator, and the pages are served with a Content-Security-Policy of connect-src 'none': the browser itself refuses to let the page make any network request. Open your developer tools while you generate and you will see nothing leave. No accounts, no cookies, no analytics scripts.

Generated it for someone else?

Every tool has a Share it as a one-time link button. It hands the value to OncePad's share form in the same tab, where it is encrypted in your browser under a generated 7-word passphrase. The link works once and expires after 24 hours — a better place for a new password than a chat message. Read how to share a password securely.