Simple Password Generator
This simple password generator does one thing, and it does it in one click. There is nothing to configure: no length to choose, no character classes to tick, no fields to validate. Press Generate and a single 16-character password appears in the field labelled “Generated Password”, built from upper case letters, lower case letters, digits and symbols with at least one of each guaranteed. Press Copy and the exact string is on your clipboard. Every character comes from the browser’s own cryptographic random source, nothing is transmitted, and nothing is stored — refresh the page and the password is gone. That narrowness is the point. This is the basic password generator for the ordinary case — one strong password, right now — and when you do need to set the length, produce a batch or exclude characters you would rather not type, the advanced password generator is the page for that.
What the Simple Password Generator Does
Strip the page down and there are three elements: a label, a read-only field and two buttons. The field always holds exactly 16 characters; the buttons are Generate and Copy. Everything else about the tool is a rule applied to those 16 characters:
- Fixed length, guaranteed composition. Every result is exactly 16 characters, and at least one character comes from each of four classes — 26 upper case letters, 26 lower case letters, 10 digits and 30 symbols. One character from each class is placed first, the remaining twelve positions are filled from the union of all 92 characters, and during that fill a candidate equal to the character before it is skipped and redrawn.
- A real shuffle. After the fill the whole array goes through a Fisher–Yates shuffle using the same crypto source, so the four guaranteed characters do not sit in fixed positions. There is no slot you can predict by looking at the string.
- An acceptance check in the OWASP style. The finished string is tested for length (at least 16) and for the presence of upper case letters, lower case letters, digits and symbols. A string that failed would be discarded and regenerated — a path the construction above already makes unreachable, kept as a guard that proves the guarantee rather than relying on it.
- Cryptographic randomness. Characters are picked with rejection sampling on
window.crypto;Math.random()is never used, and the shared fallback path is rejection sampling too. Every character in the pool is equally likely, with no modulo bias. - Nothing leaves the browser. The generator is pure front-end JavaScript: no server round trip, no upload, no account, no analytic event carrying the result. For the same reason there is no share link, by design — the calculators on this site can encode their inputs into the URL, but a password is exactly the kind of value that should never end up in a URL, a browser history or a chat log.
| Character class | Characters | Count | Share of the pool |
|---|---|---|---|
| Upper case letters | A–Z | 26 | 28.3% |
| Lower case letters | a–z | 26 | 28.3% |
| Digits | 0–9 | 10 | 10.9% |
| Symbols | !@#$%^&*()-_=+[]{};:,.<>/?`~|\ | 30 | 32.6% |
| Pool (union of the four) | all of the above, no repeats | 92 | 100% |
The two printable ASCII characters deliberately left out are the double quote and the apostrophe, because they break CSV files and SQL statements and are awkward to type on some keyboards. Space is not in the pool either — a leading or trailing space is the first thing an account form trims, which would silently shorten the password.
The labels are part of the contract, because they are the only text the tool shows you: the field is titled Generated Password, the buttons read Generate and Copy, and after a successful copy the button itself reads Copied! for two seconds before returning to “Copy”.
Formulas, Character Sets and Conventions
Five quantities describe everything this quick password generator does. The symbols used on this page are collected here first.
| Symbol | Meaning | Definition used here |
|---|---|---|
| A | upper case set | the 26 letters A–Z |
| B | lower case set | the 26 letters a–z |
| D | digit set | the 10 characters 0–9 |
| S | symbol set | the 30 punctuation characters in the table above |
| U | union of the four sets | the pool a character is drawn from, 92 characters |
| n | password length | fixed at 16 |
| H | entropy of the password | log₂ of the number of equally likely results |
The pool. Adding the four sets gives the size of the alphabet the generator draws from:
\[ |A| = |B| = 26, \quad |D| = 10, \quad |S| = 30, \qquad |U| = |A \cup B \cup D \cup S| = 92 \]
The construction. One character from each class is placed first, twelve pooled characters follow, and the whole array is shuffled:
\[ \text{password} = \operatorname{shuffle}\left( A_1,\, B_1,\, D_1,\, S_1,\, u_5, \ldots, u_{16} \right), \qquad u_i \in U \]
where \(A_1\) is one uniformly drawn character from the upper case set (and \(B_1\), \(D_1\), \(S_1\) likewise), and each of the twelve \(u_i\) is drawn uniformly from the 92-character pool, redrawn when it would equal the character before it.
The shuffle. Fisher–Yates walks the array once from the end, swapping each position with a uniformly chosen earlier one:
\[ \text{for } i = 16 \text{ down to } 2: \quad j \sim \mathrm{Uniform}\{1, \ldots, i\}, \quad \text{swap } r_i \leftrightarrow r_j \]
Why rejection sampling. A 32-bit crypto value is a number from 0 to 4,294,967,295, and that range is not a multiple of 92. Taking a remainder directly would make the low characters slightly more likely — the modulo bias. The tool computes an acceptance limit and redraws anything above it, so all 92 characters have exactly the same probability:
\[ \text{limit} = \left\lfloor \frac{2^{32}}{|U|} \right\rfloor \cdot |U| – 1, \qquad \text{accept } x \le \text{limit}, \text{ otherwise redraw} \]
How strong 16 characters is. Entropy is the base-2 logarithm of the number of equally likely passwords. For the full printable ASCII range — 94 characters, everything a US keyboard can type except the space bar — 16 independent characters give:
\[ H = \log_2\left(94^{16}\right) = 16 \times \log_2 94 \approx 104.9 \ \text{bits} \]
That figure is the upper bound, and it is the number usually quoted for a 16-character password. Two details move the real value by a fraction of a bit and no more. First, this tool’s pool is 92 characters rather than 94 — the double quote and the apostrophe are left out — which gives \(16 \times \log_2 92 \approx 104.4\) bits. Second, guaranteeing one character from each class and never repeating a character back-to-back inside the fill removes only a sliver of the remaining space, roughly 0.3 bits of the total. Read the result as “about 104 bits”: the guarantee costs a fraction of a bit and buys the certainty that every password passes a four-class check.
Precision and boundaries. Nothing here is rounded to two decimals, because nothing here is a measurement: the result is an exact string of characters, and the only thing a display can do to it is change the font. There is no input to validate either — no positive number to type, no range to stay inside, no default to overwrite; the sole control is a button. The fixed quantities are the ones above: 16 characters, four classes, one guaranteed character from each, and a 92-character pool. There is no unit toggle and nothing to convert, because a password has no length in cm or inches and no weight in pounds — it is a string, not a physical quantity.
How to Use the One Click Password Generator
- Press Generate. The field labelled “Generated Password” is filled the moment the page loads, and every press replaces the value with a fresh 16-character password.
- Read it if you want to. You do not have to check it: the string is 16 characters long and contains at least one upper case letter, one lower case letter, one digit and one symbol, every single time. There is no field where you could have typed something wrong, because there are no fields.
- Press Copy. The whole string goes to your clipboard and the button reads “Copied!” for two seconds. If the browser refuses the clipboard call — a page served over plain HTTP will — the tool falls back to the classic select-and-copy path before giving up.
- Paste it where it is needed, ideally into a password manager first, so the password is stored before you need it a second time.
- Press Generate again for another one. There is no history on this page: the previous password disappears the moment a new one appears, so copy or save it before you click again.
When this page is enough, and when to move on. This is the easy password generator for the everyday case: you need one strong password for one account, the site asks for nothing beyond “16 characters, mixed”, and you do not want a settings panel in the way. Its one real limitation follows from the same simplicity — the length cannot be changed — and that is exactly what the advanced page is for.
| What you need | This page | The advanced generator |
|---|---|---|
| Length | fixed at 16 characters | 1 to 256 characters, slider or typed |
| How many at a time | one per click | a batch, counted |
| Character classes | all four, always on | each class can be switched off |
| Exclusions | none | exclude look-alike characters (O/0, l/1, S/5) or list your own |
| Extra safeguards | the four-class guarantee | require one from each selected class, avoid consecutive repeats |
| Feedback | the password and the Copy button | strength meter with suggestions, history of the last 50 |
Worked Examples and Output Shape
A password cannot be quoted the way a BMI or a percentage can, because the whole point is that the next click gives a different answer. What can be described exactly is the shape of the output and the rules behind it, and every figure below follows from the formulas above rather than from one lucky screenshot.
Example 1 — one click, and the shape of what appears
Press Generate once and the field holds exactly 16 characters drawn from the 92-character pool, with all four classes present. The classes are not balanced, because the pools are not the same size: symbols are 30 of the 92 characters (32.6%) and digits only 10 (10.9%), so a result usually carries more symbols than digits. Averaged over many clicks the mix settles at about 4.4 upper case letters, 4.4 lower case letters, 4.9 symbols and 2.3 digits — the four guaranteed characters plus twelve pooled draws. The digit count is the one worth knowing if you check passwords by eye: about a quarter of results hold exactly one digit, about 37% hold two and about a quarter hold three. A digit-free result is impossible; that is the guarantee doing its job. Nor is there a predictable slot: the guaranteed characters are shuffled into the string, so any of the 16 positions can hold any of the four classes.
Example 2 — what the Copy button puts on the clipboard
Press Copy and the clipboard receives the exact 16 characters shown in the field — the same string, character for character, including the symbols that are hardest to retype by hand. The button changes to “Copied!” for two seconds and then returns to “Copy”; the field itself never changes. Nothing else happens: no confirmation dialog, no email, no log entry. If the clipboard write is blocked, the tool falls back to the classic hidden-field select-and-copy method before reporting a failure.
Example 3 — a second click, and what it costs
Press Generate again and a completely new password is drawn from scratch; the previous one disappears from the page. That is a deliberate simplification, not an oversight: the basic tool keeps no history at all, so if you are generating a password to keep, put it in a password manager or copy it before clicking again. There is also no undo — nothing about the old password was stored anywhere, including in your own browser, so it cannot be recovered from the page.
Example 4 — what the four-class guarantee actually buys
Take 16 characters at random from the same 92-character pool and there is a real chance the result would be rejected by a composition rule: a blind draw misses at least one class about 17% of the time, and in about 16% of blind draws it is the digit that is missing — \( (82 \div 92)^{16} \approx 15.9\% \). This generator never relies on that luck. It places one character from each class first, then fills and shuffles, so the OWASP-style acceptance check at the end is a verification step rather than a filter that throws work away.
Simple Password Generator FAQ
Should I use this basic password generator or the advanced one?
Use this page when you need one strong password and nothing else; use the advanced generator when a site’s rules or your own workflow force a choice. This page is deliberately not configurable — 16 characters, all four classes, one click. The advanced page adds a length from 1 to 256, a batch count, per-class switches, look-alike exclusions, a custom exclusion list, a strength meter and a history of recent passwords, and those are worth having only when something requires them.
How is the password actually generated — is it really random?
Every character is drawn from window.crypto, the browser’s cryptographic random source, using rejection sampling; Math.random() is never used anywhere on this page. One character comes from each class, the rest are drawn from the 92-character pool, and the finished array is shuffled with the same source, so the characters are both unpredictable and evenly distributed. No web page can claim to be random in the physical sense, but this is cryptographic randomness, which is the property that matters: seeing earlier passwords tells you nothing about the next one.
Does the password leave my device or get stored anywhere?
No. The password is generated inside your browser and nothing is transmitted, stored or logged. There is no server endpoint, no account and no sharing feature, so there is nothing to look at on the network side. The tool does not even offer a share link, unlike the calculators on this site: a link is fine for a BMI figure, but a password in a URL ends up in history, in logs and in whatever you paste it into. Refresh the page and the current password is gone.
Why is the length fixed at 16 characters with all four classes?
Because 16 characters with all four classes satisfies almost every account policy in current use, and asking you to configure it every time is the friction this page exists to remove. It is also where the security comes from: 16 characters over the 92-character pool is about 104 bits of entropy, and length is the factor that moves that number fastest — every extra character multiplies the guessing work by roughly 92. If a service insists on 20 or 32 characters, or on a smaller alphabet, the advanced generator is the page to use.
Could the same password be generated twice?
Only in theory — the space of possible results is on the order of 10³¹ strings, so a repeat is not a realistic concern. The practical risk is not a collision in the generator, it is repetition by the person: using the same password on two accounts, or a variant with a trailing digit, is what turns one breach into ten. Generate a fresh password per account and let a password manager hold them all; that is exactly the workflow this one click password generator is built for.
Is a 16-character password from this page strong enough for email or banking?
Yes: around 104 bits of entropy is far beyond what brute-force guessing can reach, provided the password is used on one account only. What breaks accounts in practice is reuse, phishing and services that store passwords badly — the generator removes the weak-password problem, not those. So generate one password per account, save each in a password manager, and turn on two-factor authentication wherever it is offered. For a batch of passwords, or for a length your bank’s form demands, switch to the advanced generator.
Related Tools
The advanced password generator is this page’s direct sibling: same cryptographic core, plus length and count controls, per-class switches, exclusions, a strength meter and history — worth the extra controls when a policy has to be satisfied. When the secret you need is a token or an ID rather than something you log in with, the random string generator draws strings from character sets you choose, with the same crypto source and a copy button. And when the value you want is a number rather than a secret — a draw, a sample, test data — the random number generator handles single values and batches of up to 10,000.