ALL DEVELOPER TOOLS56
Password Generator
Password Generator — Strong & Cryptographically Secure
Generate random passwords with customizable length, character types, and strength meter.
About Password Generator
Weak and reused passwords are the leading cause of account breaches and unauthorized access. Creating truly random passwords is something humans are notoriously bad at — we tend to use predictable patterns, dictionary words, and personal information that attackers can guess. This tool generates cryptographically secure random passwords using the Web Crypto API (crypto.getRandomValues), which provides the same quality of randomness used in encryption and security protocols, drawn without the modulo bias a naive generator introduces. Customize the length from 8 to 128 characters and toggle character types including uppercase letters, lowercase letters, numbers, and symbols to meet any password policy requirements — every class you tick is guaranteed to appear at least once. A strength meter rates each result Weak, Fair, Strong, or Very Strong from the entropy implied by its length and character mix. Bulk generate up to 20 passwords at once for setting up multiple accounts or creating credentials for a team. Copy any password to your clipboard with a single click.
Questions
Are generated passwords stored anywhere?
No. Passwords are generated using the Web Crypto API in your browser and are never stored or transmitted. Close the tab and they're gone.
What does the strength meter measure?
It calculates the entropy (randomness) of the password based on its length and the character pool size. Higher entropy means more possible combinations and a stronger password.
How long should my password be?
For most accounts, 16 characters with mixed case, digits, and symbols puts you well past 80 bits of entropy — comfortably out of reach of brute force. For high-value accounts or master passwords, aim for 24+ characters.
Is every character type I check guaranteed to appear?
Yes. One character from each checked class is picked first (as far as the length allows), the rest are drawn from the combined pool, and the result is shuffled — so a 16-character password with Symbols checked will never happen to contain zero symbols.
Are some characters more likely than others?
No. The generator uses rejection sampling on 32-bit random draws instead of a plain modulo, which removes the slight statistical bias toward early pool characters that naive generators have. Every character in the pool has an equal chance on each draw.
Is my file uploaded to a server?
No. Transmute processes everything locally in your browser using JavaScript and WebAssembly. Your files never leave your device — there is no server, no upload, no cloud processing.