---
title: "Password Generator"
description: "Cryptographically secure random passwords with length, character sets, and ambiguous-character control. Generated locally, never transmitted."
url: "https://freshjuice.dev/tools/password-generator/"
---
## About this tool

Passwords are generated with `crypto.getRandomValues` and unbiased rejection sampling (the same approach Bitwarden uses to avoid modulo bias), then shuffled with a secure Fisher–Yates pass. Nothing is logged or sent over the network — you can watch the Network tab while generating.

## Tips

-   **Length beats complexity.** A 20-character password from a letters+numbers pool has more entropy than a 10-character one with symbols.
-   **Ambiguous characters** (`l`, `1`,`O`, `0`) are excluded by default so passwords survive being read aloud or typed from a printout.
-   The strength meter shows entropy: length × log₂(pool size). 70+ bits is strong; 100+ is overkill in the best way.

## Frequently Asked Questions

### Are these passwords really random and secure?

Yes. Randomness comes from `crypto.getRandomValues`, the Web Crypto API backed by your OS's cryptographically secure random source. Selection uses rejection sampling so every character in the pool has exactly equal probability (no modulo bias), then a secure Fisher-Yates shuffle distributes them. Bitwarden uses the same approach.

### How long should my password be?

Longer beats more exotic. A 20-character password from just letters and numbers has about 125 bits of entropy, far beyond any realistic brute-force attack. An 8-character one with symbols has ~52 bits and falls to GPU cracking rigs in hours. Aim for 16+ characters; go 20+ for anything guarding money or identity.

### Why does the same length sometimes show different strength?

The strength meter computes entropy from the actual character pool of the last generated password: length × log₂(pool size). Toggle a character set on or off and the pool changes, so the same length scores differently. More possible characters means more guesses needed per position.

### Does the tool ever send my password anywhere?

No. Generation, strength calculation, and copy-to-clipboard all happen locally in your browser. No server component, no logging, no analytics on the generated value. Watch the Network tab: the page makes zero requests while you generate.

### Should I use a generated password or a passphrase?

Both work if the entropy is equivalent. A generated 20-character random string has ~125 bits; a five-word passphrase from a 7,776-word list (diceware) has ~64 bits, weaker on paper but longer and often easier to remember and type. For passwords a manager will store anyway, random strings are better. For ones you must type from memory, passphrases win.

### What are ambiguous characters and why exclude them?

Some glyphs look alike across fonts and handwriting: lowercase `l` vs digit `1`, capital `O` vs `0`, `I` vs `l`. Excluding them (on by default) means a password read aloud over the phone or typed from a printout can't be mis-transcribed. The entropy cost is a rounding error.
