Made on your device
Passwords are created by your own browser. This page has no server-side code at all.
Free · No sign-up · Nothing stored
Create secure, random passwords and passphrases in one click. It all happens in your browser: nothing is saved, logged or sent anywhere.
Your passwords never leave this page. They're made right here in your browser. Nothing is saved, logged or sent anywhere, so use it freely.
Passwords are created by your own browser. This page has no server-side code at all.
No database, no cookies, no analytics. We never see your passwords, so there is nothing to leak.
Built on the Web Crypto API, the same secure random source browsers use for encryption.
How it works
Choose a length and character types, or switch to an easy-to-remember passphrase.
Your browser creates a new random password instantly. It is never sent anywhere.
One click copies it. Save it in your password manager. Close the tab and it is gone from here.
Stay safe
A strong password is long, random and unique. Random characters from a large set make it practically impossible to guess, even for a computer trying billions of combinations per second.
FAQ
Yes. PassGen is completely free, with no sign-up, no limits and no ads. Generate as many passwords as you like.
No. Every password is created inside your own browser and never leaves your device. There is no server, database, account or log involved, so we have nothing to store and nothing to see. Close the tab and it is gone.
It depends on where the password is created. Many online generators build passwords on a server, so you have to trust them. PassGen creates passwords only inside your browser and never sends them anywhere. You can check this yourself: open your browser's developer tools, go to the Network tab and generate a few passwords. You'll see no requests.
PassGen uses the Web Crypto API (crypto.getRandomValues), the same cryptographically secure random source browsers use for encryption. It also uses rejection sampling so every character is equally likely.
Use at least 16 characters with a mix of letters, numbers and symbols for important accounts. Longer is always stronger: every extra character multiplies the number of guesses an attacker needs.
A passphrase is a string of random words, like Maple-Tiger-Ocean-Violin. It is easier to remember and type than random characters. Use seven or more words for strong protection.
The meter measures entropy: how many guesses an attacker would need, based on the length and the number of possible characters or words. Crack times assume a powerful offline attack of 100 billion guesses per second. Aim for "Strong" or "Very strong".
Yes. Once the page has loaded, generating passwords needs no internet connection because nothing is sent anywhere.