Strength: Weak0 bits
Strong password generator
Long, random, unguessable passwords. They are made only in your browser; never sent anywhere and never stored.
Passwords come from your browser's cryptographic random number generator (crypto.getRandomValues). The page never sends a password to a server.
Strength is shown in bits: every extra bit doubles the guessing time. 80 bits and above resist online attacks; 100 bits and above stay safe for a very long time.
Frequently asked questions
How long should my password be?
We recommend at least 16 characters. Use a different password for every account and keep them in a password manager.
What does excluding similar characters do?
It drops characters that are easy to confuse, like 0/O and 1/l/I; useful if you will type the password by hand.
Are these passwords really random?
Yes. The browser's cryptographic random number generator is used and every character is chosen with equal probability.
With Colitu, sites see our server's address instead of your real IP. 10 GB free every month. Download the app →
The tools do not store your results. The DNS test keeps a random ID in memory for ten minutes; the other tools run only in your browser.