Password Generator (Advanced)
This password generator builds credentials to a policy you set: length from 1 to 256 characters, four independent character types, two kinds of exclusion, a rule that forces at least one character of every type you picked, a rule against two identical characters in a row, and a batch size of up to 50. It is the configurable sibling of the basic password generator — that page always returns a 16-character password from a fixed recipe, while this one is where the policy lives. Use it to create password strings for your own accounts, to generate password batches for a class or a test environment, or simply to see what a strength meter is really counting. Everything runs in your browser: the characters are drawn from window.crypto, nothing is uploaded, and unlike the calculators on this site there is deliberately no share link, because a link that carries a password is a password posted in public.
Strength
History
Generated: 0 times
What This Password Generator Does
Strip away the buttons and the job is simple to state: produce a string of characters that nobody can predict, with the option to shape it until the site that demands it accepts it. That makes this a random password generator first, and the same engine answers to the other names people arrive with — a strong password generator for a new account, a secure password generator for anything holding money or health data, and a password maker that a teacher or a developer can point at a whole batch of throwaway accounts at once. What separates it from a decorative generator is not the button, it is the source and the options. Password creation is a policy decision as much as a click, and this page is where that policy gets written down: how long, which characters, what to leave out, and what a website’s rules will let you submit.
- Length to order — 1 to 256 characters. The slider and the number field are linked, and the page opens at 16.
- Batches of up to 50 — the block’s count attribute decides how many passwords one Generate click produces, and the output box holds them one per line. It is the fastest way to generate strong passwords for a whole classroom or a test environment in one sitting.
- Four character types — uppercase, lowercase, numbers and symbols, each with its own checkbox. Every type you tick makes the pool the characters are drawn from larger, and the default is the first three with symbols off.
- Two exclusions — the “Exclude similar” option strips the characters that are easy to confuse when you read a password back (O 0 o I l 1 S 5 Z 2 B 8), and the “Exclude characters” field removes anything you type into it.
- Two policy rules — “Require one from each selected” guarantees at least one character of every type you checked, and “Avoid consecutive repeats” refuses to place the same character twice in a row.
- A strength meter — six binary checks, one bar, and a reading of Weak, Medium or Strong, computed from the first password of the batch.
- A 50-entry history — every password you generate stays on the page with its own Copy button, next to a counter and a Clear history button. Nothing is stored anywhere else.
Three limits are worth stating plainly, because they decide whether this is the right page. It is a character-based generator, not a passphrase generator: there is no word list and no diceware mode, so a memorable “four random words” password is out of scope here. It is not a password keeper — nothing survives beyond the on-page history, and that history disappears when you close the tab, so the password has to go into a password manager or a notebook that is not this page. And it does not check your new password against breach lists: it can guarantee that the string is unpredictable, not that the website you are signing up for will store it safely.
Why the source matters. Randomness comes from window.crypto with rejection sampling, and Math.random() is never used. Rejection sampling matters in the details: a 32-bit random value is not a clean multiple of every pool size, so scaling it or taking a remainder would give the first characters in the set a slightly higher chance of appearing. The tool instead redraws anything above an acceptance limit, so every character in the pool has exactly the same probability. Passwords are also generated on your own device — no web service, no account, no server round trip — which is the only version of “generated securely” that a browser page can honestly promise.
Formulas and Character Sets
Three quantities describe everything the tool produces: how big the pool is, how many strings that pool can make at the length you chose, and how much of the strength meter lights up. The symbols below are the ones used on this page.
| Symbol | Meaning | Definition used here |
|---|---|---|
| U | uppercase pool | A–Z, 26 characters; 21 once similar characters are excluded |
| L | lowercase pool | a–z, 26 characters; 24 with similar characters excluded |
| D | digit pool | 0–9, 10 characters; 5 with similar characters excluded |
| S | symbol pool | the 30 punctuation characters listed in the table below |
| N | size of the pool the tool draws from | N = U + L + D + S, which is 92 when all four types are on |
| ℓ | password length | 1 to 256 characters, default 16 |
| score | strength score | 0 to 6, one point per check that passes |
| P | chance a single guess hits the password | 1 ÷ Nℓ |
The pool. Each checkbox contributes its own set, and the sets are unioned before anything is drawn:
\[ N = U + L + D + S = 26 + 26 + 10 + 30 = 92 \quad \text{(all four types selected)} \]
How many strings exist. Every position is drawn independently from the pool, so the count of possible passwords grows exponentially with the length:
\[ \text{possible strings} = N^{\ell}, \qquad \text{entropy} = \ell \times \log_2 N \ \text{bits} \]
Read the same expression backwards and you have the chance that a single guess lands on one particular password — which is why length is the cheapest strength there is:
\[ P(\text{one guess hits}) = \frac{1}{N^{\ell}} = \frac{1}{92^{16}} \approx \frac{1}{2.63 \times 10^{31}} \]
The strength score. The meter is a checklist, not a crack-time estimate. It awards one point for each of six conditions and turns the total into a word:
\[ \text{score} = [\ell \ge 8] + [\ell \ge 12] + [\text{uppercase}] + [\text{lowercase}] + [\text{digit}] + [\text{symbol}], \qquad \text{width} = \frac{\text{score}}{6} \times 100\% \]
The same six points decide the label: fewer than three is Weak, three or four is Medium, and five or six is Strong. Note what is not in the formula — nothing about common words, keyboard walks or reused passwords, so a 16-character string that is a well-known phrase still scores six. The meter measures the policy you applied, not the secrecy of the result.
| Score | Reading | What it means |
|---|---|---|
| 0 – 2 | Weak | fewer than three checks pass — usually short, or drawn from a single type |
| 3 – 4 | Medium | three or four pass — for example 8 characters with letters and digits |
| 5 – 6 | Strong | five or six pass — at least 12 characters with a mix of types |
| Checkbox | Characters | Count |
|---|---|---|
| Uppercase | ABCDEFGHIJKLMNOPQRSTUVWXYZ | 26 |
| Lowercase | abcdefghijklmnopqrstuvwxyz | 26 |
| Numbers | 0123456789 | 10 |
| Symbols | !@#$%^&*()-_=+[]{};:,.<>/?`~|\ | 30 |
| Exclude similar removes | O 0 o I l 1 S 5 Z 2 B 8 | 12 in total: 5 uppercase, 2 lowercase, 5 digits |
The exclusions shrink the pool. Excluding similar characters takes five uppercase letters, two lowercase letters and five digits out of the sets above while leaving the symbols untouched, so the four-type pool drops from 92 characters to:
\[ N = (26 – 5) + (26 – 2) + (10 – 5) + 30 = 80 \]
The “Exclude characters” field subtracts however many distinct characters you list, and if a set is emptied completely it simply stops contributing to the pool rather than being refilled.
What each configuration is worth. The table below applies the two formulas above; the entropy column is the length multiplied by log2 of the pool.
| Configuration | Pool N | Possible strings | Entropy |
|---|---|---|---|
| Lowercase only, 16 characters | 26 | 2616 ≈ 4.36 × 1022 | log2(2616) ≈ 75.2 bits |
| Letters and digits, 16 characters (the page default) | 62 | 6216 ≈ 4.77 × 1028 | log2(6216) ≈ 95.3 bits |
| All four types, 16 characters | 92 | 9216 ≈ 2.63 × 1031 | log2(9216) ≈ 104.4 bits |
| All four types, 32 characters | 92 | 9232 ≈ 6.94 × 1062 | log2(9232) ≈ 208.8 bits |
| All four types with similar characters excluded, 16 characters | 80 | 8016 ≈ 2.81 × 1030 | log2(8016) ≈ 101.2 bits |
One note on the pool size, because it is the number people quote most often. Many generators describe their alphabet as the 94 printable ASCII characters; this tool’s four sets add up to 26 + 26 + 10 + 30 = 92, because its symbol list leaves out the two quote marks. The familiar 94-character pool gives log2(9416) ≈ 104.9 bits at sixteen positions — half a bit more than the 104.4 bits in the table, which is the whole difference between the two figures. What actually moves the number is the length and the number of types selected, not the last two punctuation marks.
Precision and boundaries. Nothing here is rounded to two decimals: a password is a string, not a measurement, so every character is kept exactly as it was generated and there is no display cut-off to reason about. Length and batch size are counts, so both must be positive numbers — length 1 to 256, batch 1 to 50 — and a length outside the range is corrected automatically (the hint under the field reads “Use slider or input. Out-of-range will auto-correct.” and the error line reads “Length must be between 1 and 256.”). With require-each switched on there is a second boundary: the length must be at least as large as the number of selected types, because you cannot fit one character from each of four sets into three positions. And no unit conversion exists on this page, because none is needed — the same 16 characters would be 16 characters whether you would have written a desk height as 5 ft 9 in or 175 cm.
How to Use the Advanced Password Generator
- Set the length. Drag the slider or type into the number field — the two stay linked, so whichever you touch updates the other. Values from 1 to 256 are accepted, and anything outside that range snaps back to the nearer boundary.
- Tick the character types you need: Uppercase, Lowercase, Numbers, Symbols. Leave at least one ticked — with none selected the tool refuses to run and answers “Please select at least one character type.” rather than falling back to a default set.
- Decide what to leave out. “Exclude similar (O0, l1, S5)” removes the twelve characters that look alike in most fonts, which makes a password easier to read back from paper; the “Exclude characters” field takes any list of characters you type and drops them from every selected set, as its hint says: “Characters in this list will be removed from sets.” This is the place to exclude a character your legacy system rejects, or a quote mark your shell will swallow.
- If the site has a password policy, switch on the rules that mirror it: “Require one from each selected” for sites that demand a capital, a digit and a symbol, and “Avoid consecutive repeats” for the ones that reject doubled characters. If the length is too short for the first of those, the tool tells you instead of quietly ignoring the checkbox: “Length must be at least {n} to include one character from each selected type.” — where {n} is the number of types you selected, so with all four ticked it reads “Length must be at least 4 to include one character from each selected type.”
- Press Generate. The output box fills with the password, or with one password per line when the block’s count attribute asks for a batch of up to 50.
- Read the strength meter under the output and copy what you need. Copy takes the whole output box, so a batch of three is copied as three lines; each history row also has its own Copy button for a single password.
- Check the History panel if you are filling in several accounts in one sitting. The newest is on top, the list keeps the last 50, and the counter beside it reads “Generated: {n} times”. Clear history empties the list and sets that counter back to 0.
A page that embeds this tool can open with the settings already filled in, using the shortcode attributes: [app_password length="32" symbols="true"] starts every visit at 32 characters with symbols on. The available attributes are count (1 to 50, default 1), length (1 to 256, default 16) and the four switches uppercase, lowercase, numbers and symbols (true or false; the first three default to true and symbols defaults to false). They set the starting state only — everything remains changeable in the interface, and the batch size is read from the count attribute on the page rather than typed in.
Worked Examples
The generated strings themselves cannot be quoted here, because any fixed example would be exactly the thing the tool exists to avoid. So each example below describes what one configuration returns — the length that comes out, the guarantee that holds inside it, how many different strings the pool could have produced, and what the meter reads. Every number is the arithmetic from the formulas above, not a screenshot.
Example 1 — one 16-character password, the default length
Open the page and press Generate, and the output box holds a single line that is exactly 16 characters long — no more, no fewer, and with the length field and slider both sitting at 16. Where those characters come from depends on the ticks. With lowercase alone the pool is 26, so the line is one of 2616 ≈ 4.36 × 1022 possible strings and carries log2(2616) ≈ 75.2 bits of entropy. Tick the other three boxes as well and the pool becomes 92 characters, so a 16-character password is one of 9216 ≈ 2.63 × 1031 strings, worth log2(9216) ≈ 104.4 bits — a gain of about 29 bits for three extra clicks, which is why the character-type checkboxes on every signup form exist. Switch on “Require one from each selected” and the output keeps its length while gaining a guarantee: at least one uppercase letter, one lowercase letter, one digit and one symbol sit inside those 16 positions, in an order that is shuffled so their placement gives nothing away. The meter passes all six checks, so the label is Strong. What you cannot do is recognize the output: it will look like noise, and it should.
Example 2 — one 32-character password for a vault master
Set the slider to 32, or load a page that starts there with [app_password length="32" symbols="true"], and press Generate. The output is one 32-character line, and with all four types selected it is a single string out of 9232 ≈ 6.94 × 1062 — an entropy of log2(9232) ≈ 208.8 bits, twice the 16-character figure, because the bits grow in step with the length while the number of strings multiplies by 92 for every extra position. Two consequences are worth knowing. First, the strength meter does not move: it was already at six of six at 16 characters, and length beyond 12 no longer buys a point, so the meter is a policy checklist rather than a measure of the extra entropy you just added. Second, a 32-character string is past the point where typing it by hand is realistic — this is the length for a password manager’s master password or an encryption key you will paste, not something to retype from memory on a phone.
Example 3 — three 8-character passwords in one click
A page configured with [app_password length="8" count="3"] returns three passwords per click, one per line in the output box. Take the page defaults — uppercase, lowercase and numbers, symbols off — and each line is drawn from a pool of 62 characters, so one 8-character password is a single string out of 628 ≈ 2.18 × 1014, or log2(628) ≈ 47.6 bits. The meter reads Medium rather than Strong, and the arithmetic shows why: the score is four of six, picking up points for the 8-character length, the uppercase set, the lowercase set and the digits, but missing the two for reaching 12 characters and for adding a symbol. Eight characters is the floor that most sites still accept, not a target to aim for — if a service forces 8, keep everything else maxed and switch symbols on. The history panel shows what a batch does: three new rows appear, newest first, each with its own Copy button, and the counter beside them reads “Generated: 3 times” — the total counts every password ever generated on the page, not every click, and Clear history resets it to zero.
Password Generator FAQ
Is this password generator safe to use?
Yes, with the usual browser caveat: the passwords are created on your own device and nothing you type or generate is sent anywhere. The characters come from window.crypto through rejection sampling, so no character in the pool is favoured, Math.random() is never used, and there is no upload, account or server round trip for a value to pass through. The genuine risk is not the generation step but what you do next — copying the password through a chat app or leaving it on a shared clipboard is where secrecy is usually lost.
How long should my password be?
Use 16 characters as your default and never go below 12 for anything that matters. Length is the cheapest strength there is, because each extra character multiplies the possibilities by the pool size: 16 characters from all four sets sit at log2(9216) ≈ 104.4 bits, and 32 characters double that to log2(9232) ≈ 208.8 bits. The character types matter far less than the length, which is why the strength meter gives two of its six points to length alone.
What does “Require one from each selected type” actually do?
It guarantees that the finished password contains at least one character from every type you ticked, which is what most signup forms check. The tool places one character from each selected set first, shuffles them so their positions are not predictable, and then fills the rest of the length from the combined pool. If the length is too short to hold one of each, it refuses instead of silently dropping the guarantee: “Length must be at least {n} to include one character from each selected type.”, where {n} is the number of selected types — with all four ticked, “Length must be at least 4 to include one character from each selected type.”
Should I exclude similar characters?
Exclude them when a human has to read or retype the password — printing it, writing it down, reading it over the phone — and leave them in when the password goes straight into a password manager. The option removes twelve characters that are easy to mistake for each other (O 0 o I l 1 S 5 Z 2 B 8) from every selected set, which shrinks a four-type pool from 92 characters to 80 and the entropy of a 16-character password from about 104.4 bits to log2(8016) ≈ 101.2 bits. That is a loss of roughly 3 bits, the price of legibility, and it is a good trade for a password you have to transcribe by hand.
What does the strength meter actually measure?
Six yes-or-no checks: whether the password is at least 8 characters, whether it is at least 12, and whether it contains an uppercase letter, a lowercase letter, a digit and a symbol. Each check is worth one point out of six, the bar fills to that fraction, and the label is Weak below three, Medium at three or four and Strong at five or six — measured on the first password of the batch, not on an average. It is a policy checklist rather than a crack-time estimate: it knows nothing about dictionary words, reused passwords or a pattern like “Abcdef123456!”, all of which can pass six of six.
How is this different from the basic password generator?
The basic password generator does one thing: a fixed 16-character password from a fixed recipe, one click, one copy button. This page is the version with a policy — length from 1 to 256, batches of up to 50, four character sets you can mix, similar-character and custom exclusions, require-each and no-repeat rules, a six-point strength meter and a 50-entry history. If you just want a fast 16-character password, the basic page is quicker; if the site imposes rules, this is the page that can follow them.
Why is there no share link for a password?
Because the sharing feature on this site works by encoding the inputs into the URL, and a password is not an input — it is the entire secret. A link carrying “length 16, symbols on” would be harmless, but the moment the same mechanism shipped here, someone would paste a link containing an actual password into a group chat, an email or a support ticket. The password-type tools on this site therefore deliberately have no share button; copy the result instead, and send it through a channel you would trust with the password itself.
Does the tool keep or store my passwords?
Only in the History panel on the page itself, which keeps the last 50 passwords you generated, newest first, so you can copy one you have already moved past. Each row has its own Copy button, the counter beside the list counts every password generated so far, and Clear history empties the list and resets that counter to 0. Nothing goes to a server, and the list disappears when you close the tab — so if the password matters, save it in a password manager before you navigate away.
Related Tools
Three pages sit next to this one. If you only need one quick password and no options, the basic password generator is the shorter path. When the string you need is not a secret at all — an order number, a coupon code, a test token — the random string generator draws from the same character sets with its own length and batch controls. And when the thing you are generating has to be a number rather than text — a prize draw, a dice roll, a batch of sample IDs — the random number generator covers integers inside a range you set. All three use the same browser-side crypto source, and none of them sends your input anywhere.