Strong, high-entropy passwords and passphrases, generated entirely in your browser.
Every character comes from crypto.getRandomValues, the browser's cryptographically secure RNG.
Rejection sampling discards skewed values, so no character is more likely than any other.
Live entropy estimate and zxcvbn pattern detection score every password you generate.
No network requests, no analytics, no storage. Passwords never leave your browser tab.
Configure your settings above and generate a password to see it here.
Every password is scored locally in your browser, with no need to test it anywhere else.
Bits of entropy from your chosen length and character set. The more bits, the more guesses an attacker needs.
Detects dictionary words, keyboard walks, repeats, and common substitutions that raw entropy alone misses.
How long a sustained 1-trillion-guess-per-second attack would take, on average, to find your password.
Never paste a real password into any website to “check” it, including ones that claim to run locally. A password you intend to use should only ever be typed into the account it belongs to. The analysis above happens entirely in this tab and is never sent anywhere.