Skip to content
VaultPass

Tool · Local generation

A different password for every account

Pick the length and the character types and get a genuinely random key. It is generated on your device and disappears when you close the tab.

Cryptographic randomness

Close-up of typewriter keys
AVloFu_DLci08sB{iigo
Security level:
Impenetrable
129 bits of entropyIt would hold for: Longer than the age of the universe

It is placed at a random position to help you remember the password. Careful: the part you choose adds no real security.

20

Generated with crypto.getRandomValues(), the browser's secure random source.

Recent History

Your previous passwords will appear here.

History lives in memory only: reloading the page wipes it.

Let's be honest: your current password is a danger

Are you still using your pet's name followed by a "123"? I get it, it's easy to remember, but you are laying down a red carpet for any bot. Today, a normal computer can crack an 8-letter password in less than a second.

The fix is not memorising hieroglyphs: it is length (16 characters or more), never reusing the same password twice, and turning on two-step verification wherever you can. That way a leaked site stays a leaked site.

Why a machine does this better than you

When a person tries to invent something random, they fail. We tend to alternate consonants and vowels, avoid repeating characters in a row, start with a capital and finish with a digit or an exclamation mark. These are unconscious biases, and they are remarkably consistent from one person to the next.

Cracking software knows those biases and tries the combinations that follow them first. The upshot is that a password "made up at random" has, in practice, far less strength than its length suggests.

A generator has no preferences. Every character comes from a cryptographic randomness source, with no pattern anyone can get ahead of. That is the difference between looking random and being random.

What length to choose

UseLengthWhy
Ordinary accounts16 charactersBeyond the reach of any realistic attack, and your manager types it for you.
Email, banking, manager20 or moreThese are the accounts everything else is recovered from.
Services with a character limitThe maximum they acceptIf the cap is low, turn on two-factor authentication without fail.

If a site refuses to let you paste from your manager — it happens more than it should — use a passphrase of random words instead: it types cleanly and keeps its strength.

The step almost everyone skips

Generating an excellent password with nowhere to put it always ends the same way: it gets written on a note, forgotten, reset, and eventually replaced by the same old key.

Before you generate, decide where it is going to live. A password manager stores it, fills it in automatically and, as a side effect, protects you from phishing: on a fake site the manager does not recognise the domain and offers nothing. That hesitation is a free alarm.

What you do not need to do

  • Change it every three months. The bodies that popularised that rule stopped recommending it years ago.
  • Memorise it. If it is genuinely random, it was never meant for that.
  • Add a number at the end "to make it safer". If it is already random, any manual tweak only introduces a pattern.

Frequently asked

Common questions

Are the passwords generated here genuinely random?

They come from the browser’s cryptography API, which is designed for security use, rather than from JavaScript’s ordinary random number generator, which is predictable and must never be used for this.

Is anything I generate stored?

No. Generation happens on your device, nothing is sent to a server, and the history disappears when you close the page. Copy it into your manager before you leave.

How many characters should I use?

Sixteen random characters cover any normal account with room to spare. For a master password or your main email, go to twenty, or use a passphrase of random words.

Is dropping the symbols a problem?

No, as long as you compensate with length. Some older services reject certain symbols; in that case add three or four more characters and the strength ends up the same or better.

Where to go next