Keysmith

Strong, high-entropy passwords and passphrases, generated entirely in your browser.

100% client-side · Zero data stored · No network requests

Browser CSPRNG

Every character comes from crypto.getRandomValues, the browser's cryptographically secure RNG.

Unbiased Selection

Rejection sampling discards skewed values, so no character is more likely than any other.

Strength Analysis

Live entropy estimate and zxcvbn pattern detection score every password you generate.

100% Client-Side

No network requests, no analytics, no storage. Passwords never leave your browser tab.

Password Configuration

16
864
Lowercase
a–z
Uppercase
A–Z
Numbers
0–9
Symbols
!@#…
Exclude ambiguous characters
0, O, l, 1, I

Configure your settings above and generate a password to see it here.

Strength is analyzed right here

Every password is scored locally in your browser, with no need to test it anywhere else.

Entropy estimate

Bits of entropy from your chosen length and character set. The more bits, the more guesses an attacker needs.

zxcvbn pattern analysis

Detects dictionary words, keyboard walks, repeats, and common substitutions that raw entropy alone misses.

Crack-time estimate

How long a sustained 1-trillion-guess-per-second attack would take, on average, to find your password.

Never paste a real password into any website to “check” it, including ones that claim to run locally. A password you intend to use should only ever be typed into the account it belongs to. The analysis above happens entirely in this tab and is never sent anywhere.