🔐 Password Generator
Cryptographically secure random passwords with a strength meter. Nothing is stored or sent to a server.
—
Password Length
16
Select at least one character type
16
Length
0
Entropy (bits)
0
Character pool

Password Generator Online

A free strong password generator that uses the browser’s cryptographically secure random number generator (Web Crypto API) — not plain Math.random(), which is predictable and unsuitable for security. Everything happens locally: your password never leaves your browser or gets sent to any server.

What makes a password strong

Cryptographic randomness
Uses crypto.getRandomValues() — the same mechanism used by browser-based password managers, instead of predictable Math.random().
window.crypto.getRandomValues()
Strength meter
Calculates the password’s entropy in bits (length × log2 of the pool size) and shows a level: weak, average, strong, very strong.
16 chars + all types ≈ 95+ bits
Exclude ambiguous characters
Optionally removes characters that are easy to confuse when typed manually: 0/O, 1/l/I.
0, O, 1, l, I → excluded

When this is useful

  • Creating a password for a new account
  • Replacing a weak or reused password
  • Setting up a Wi-Fi router password
  • Generating temporary or one-time passwords
  • Creating passwords for shared team accounts
  • Meeting corporate password complexity requirements

How to use it

  1. Set the password length with the slider (16+ characters recommended)
  2. Toggle the character types you need: uppercase, lowercase, numbers, symbols
  3. Optionally enable excluding ambiguous characters
  4. Copy the generated password with the “⎘” button

Frequently asked questions

How secure is this generator?
The tool uses the Web Crypto API (crypto.getRandomValues()) — a cryptographically secure source of randomness recommended for password generation, unlike Math.random(), which is predictable and unsuitable for security.
What password length is considered strong?
Modern security guidance recommends at least 16 characters combining uppercase, lowercase, numbers, and symbols. This provides over 90 bits of entropy — practically impossible to brute-force.
Does the site store my passwords?
No. The password is generated and displayed entirely in your browser using JavaScript. No data is ever sent to kyrlat.com’s server or any other server.
What does password “entropy” mean?
Entropy in bits shows how many attempts an attacker would need to brute-force every possible password of that length and character set. The higher the number, the stronger the password.
Why exclude ambiguous characters?
Characters like 0/O and 1/l/I look nearly identical in some fonts, making manual entry harder (for example, when reading a password aloud over the phone). This option removes them from the generation pool.