Unique beats reused
A strong password reused across services can still fall to credential stuffing after one breach. Use a password manager and a different secret for every account.
Generate unpredictable passwords, memorable random passphrases and independent recovery codes with honest strength explanations — entirely inside this tab.
There is no account, breach lookup, analytics field or server endpoint receiving generated or entered secrets. Nothing is stored in localStorage. Closing or clearing the page discards the current workspace.
Choose a mode
Uniform rejection sampling avoids modulo bias and, when requirements are enabled, produces only strings containing every selected group.
Words are selected independently and uniformly with replacement. Ten words provide exactly 80 bits before optional digits or a symbol. This is an ordinary passphrase generator — never use its output as a cryptocurrency wallet seed phrase.
Keeping or rejecting outputs based on personal preference can reduce unpredictability. Generate once, store it safely and use it for one purpose only.
Every code is generated independently. These are printable backup codes for systems you control; they are not time-based one-time passwords, cryptographic keys or substitutes for server-side hashing and rate limits.
After importing codes into a real system, store the only remaining copy offline or in a trusted password manager.
Even though this page processes locally, good security practice is not to paste a valuable existing password into random websites. Inspect a newly generated value or a disposable example whenever possible.
This checks common values and visible patterns. It does not contact a breach database and does not claim a reliable crack-time estimate.
Local assessment
For a human-chosen secret, mathematical entropy is unknown. A complex-looking pattern may still be predictable. Exact construction entropy is shown only for values generated in this tab.
Current batch
A strong password reused across services can still fall to credential stuffing after one breach. Use a password manager and a different secret for every account.
Modern guidance emphasizes allowing long passwords, checking new choices against known weak values and avoiding arbitrary periodic changes unless compromise is suspected.
Enable multifactor authentication or passkeys where available. A password generator cannot protect a device infected with malware or a convincing phishing page.