Password Generator

Build a password and show its entropy. A string with no character rules is the random string generator

What is generated

This page builds passwords and shows the entropy of the length and the character set. A string that does not force each set, and does not show bits, is the random string generator.

How to use it

  1. Length runs from 4 to 128 and starts at 20. Count runs from 1 to 20 and starts at 5.
  2. A–Z, a–z, Digits and Symbols start checked. Exclude similar characters (0 O o l 1 I |) starts checked.
  3. Generate fills the box with one password per line and writes Entropy with one decimal place.
  4. Show Example sets Length to 20, Count to 1, checks every set, leaves similar characters excluded, and generates one password. The password itself changes every time.
  5. Clear All clears the passwords and the entropy line. The length and the checkboxes stay. Copy Result copies every line.

How a password is chosen

Each selected set contributes at least one character, then the rest of the length is filled from the combined set and shuffled. The shuffle uses crypto.getRandomValues. Length must be at least the number of selected sets.

Similar characters are 0, O, o, l, 1, I and |. With every set selected and similar characters excluded, the pool is 24 upper letters, 24 lower letters, 8 digits and 23 symbols. Entropy is the length times the base-2 log of that pool size. A 20-character password from that pool is about 126.1 bits.

Where people use it

  • Making a batch of account passwords of a fixed length.
  • Dropping characters that are easy to misread.
  • Comparing the bit strength of a short password and a long one.

Questions

Why is a short length rejected?

Each selected set needs one character. Four sets need a length of at least 4.

Is the entropy the strength of this exact password?

It is the strength of a password drawn uniformly from the pool at that length. It is not a guess about a password you typed.