Free tool

Generate credentials that survive a real attack

Everything on this page is generated inside your browser using cryptographic randomness. Nothing is transmitted, logged or stored — you can disconnect from the internet and it will still work.

Strength

Weak

Entropy

28 bits

Offline crack time

under a minute

Credentials are only half the problem

Shared logins, no MFA on admin consoles and ex-staff accounts left active cause more breaches than weak passwords. We can review your identity posture and deploy a business password manager with proper offboarding.

Password questions

Is this generator safe to use?
Yes. Everything is generated locally in your browser using the operating system's cryptographic random number generator. No password is sent to us, logged or stored anywhere.
Passphrase or random password — which should I use?
Use a long passphrase for anything you must type from memory, such as a device login or password manager master password. Use long random strings, stored in a password manager, for everything else.
How long should a password be?
Length beats complexity. Sixteen characters or four to five random words is a sensible floor for business accounts, and every account that supports multi-factor authentication should have it enabled regardless.
Should our business use a password manager?
Yes, with enforced sharing policies, MFA and offboarding controls. Deploying and administering business password managers is part of our managed IT and cyber security work.

Related: Cyber security · Essential Eight self-assessment