Free tool
Generate credentials that survive a real attack
Everything on this page is generated inside your browser using cryptographic randomness. Nothing is transmitted, logged or stored — you can disconnect from the internet and it will still work.
Strength
Weak
Entropy
28 bits
Offline crack time
under a minute
Credentials are only half the problem
Shared logins, no MFA on admin consoles and ex-staff accounts left active cause more breaches than weak passwords. We can review your identity posture and deploy a business password manager with proper offboarding.
Password questions
- Is this generator safe to use?
- Yes. Everything is generated locally in your browser using the operating system's cryptographic random number generator. No password is sent to us, logged or stored anywhere.
- Passphrase or random password — which should I use?
- Use a long passphrase for anything you must type from memory, such as a device login or password manager master password. Use long random strings, stored in a password manager, for everything else.
- How long should a password be?
- Length beats complexity. Sixteen characters or four to five random words is a sensible floor for business accounts, and every account that supports multi-factor authentication should have it enabled regardless.
- Should our business use a password manager?
- Yes, with enforced sharing policies, MFA and offboarding controls. Deploying and administering business password managers is part of our managed IT and cyber security work.
Related: Cyber security · Essential Eight self-assessment
