Password Generator

Generate strong passwords with customizable length, character types — uppercase, lowercase, numbers, symbols. Check password strength in real-time.

Batch:
Embed this tool on your website / blog No code required · Copy and paste
HTML Embed Code (iframe):
<iframe src="https://lucentool.com/password-generator" width="100%" height="650" style="border:1px solid #e5e0d8;border-radius:12px;max-width:850px;width:100%;" frameborder="0"></iframe>
<div style="font-size:12px;color:#78716c;margin-top:6px;font-family:sans-serif;">Powered by <a href="https://lucentool.com/password-generator" target="_blank" style="color:#c85a32;text-decoration:none;">Lucentool - Password Generator</a></div>

What makes a password strong?

Password strength is measured by entropy — the number of bits of uncertainty an attacker faces. Each bit doubles the guesses needed. A password with 8 bits of entropy requires at most 2⁸ = 256 guesses to crack; one with 80 bits requires 2⁸⁰ ≈ 1.2 × 10²⁴ guesses — already a septillion guesses, and a 256-bit key's 2²⁵⁶ ≈ 1.2 × 10⁷⁷ is far beyond any practical brute-force attack.

Entropy is calculated as length × log₂(N) where N is the size of the character pool. Adding more character types increases N, but length is the dominant factor. Doubling the length squares the search space, while adding symbols to a 12-character password increases entropy by only ~7 bits.

Entropy reference table

A 16-character password with all four character types (uppercase, lowercase, digits, symbols) has a pool of 91 characters in this generator: 16 × log₂(91) ≈ 104 bits — well into the "very strong" zone.

Best practices

How the Password Generator Works

All passwords are generated entirely in your browser using crypto.getRandomValues() — a cryptographically secure random number generator backed by the operating system's entropy source. Nothing is sent to any server, logged, or stored. The code is a single self-contained HTML file you can inspect, save, and run offline.