Toolbox's generator produces strong passwords, API keys, PINs, hex strings, Base64 keys and UUID v4 identifiers directly in your browser. Every character is drawn from crypto.getRandomValues - the browser's cryptographic random source - rather than Math.random, so the output cannot be predicted or reproduced.
Under the result field is a strength meter measured in bits of entropy. Entropy tells you how many attempts an attacker needs on average to guess your string: each extra bit doubles that number. Around 60 bits is too weak for modern cracking rigs, 80 bits is acceptable for an everyday password, and anything at or above 128 bits is out of reach of exhaustive search entirely.
You can pick the character sets (lowercase, uppercase, digits, symbols) or supply your own alphabet, set the length, and generate many strings at once when you need to issue initial passwords for a whole list of accounts.
Nothing you generate here leaves your machine. The page makes no network request when you press generate, keeps no log, and retains nothing once you close the tab.
What it generates
Passwords and PINs
Any length, with the character sets you choose, or digits only for a numeric PIN.
API keys and Base64 keys
Random strings long enough to serve as an application secret, token or salt.
Hex strings
Hexadecimal output for encryption keys, initialisation vectors and identifiers.
UUID v4
RFC 4122 random 128-bit identifiers, the usual choice for database primary keys.
Custom alphabet
Supply your own character set when the target system only accepts certain characters.
Entropy strength meter
A live readout so you know whether the string is long enough before you use it.
How to generate a random password
Choose the type
Pick Password, PIN, Hex, Base64, UUID v4 or a custom alphabet from the type selector.
Set the length
Drag the slider or type the character count. For an everyday password, keep it at 16 or more.
Choose the character sets
Toggle lowercase, uppercase, digits and symbols to match the rules of the system you are creating the password for.
Check the strength meter
Read the entropy figure under the result. Below 80 bits, increase the length or enable another character set.
Copy the result
Press the copy button next to the string, or raise the count first to generate a batch and copy the whole block.
Random password generator FAQ
How long should a secure password be?
With the full set of lowercase, uppercase, digits and symbols, 16 characters gives roughly 104 bits of entropy, which is enough for almost any account. For application secrets and API keys, use 24 characters or more to clear 128 bits.
What is entropy and how many bits are enough?
Entropy measures how hard a string is to guess, in bits; each extra bit doubles the number of attempts required. Below 60 bits is weak, 80 bits is the practical minimum for an account password, and 128 bits or more cannot be brute-forced by any hardware available today.
Are the generated passwords sent to a server?
No. Generation happens entirely in JavaScript in your browser. The page issues no network request when you generate, so a password never leaves your machine.
What random source does it use?
crypto.getRandomValues from the Web Crypto API, which is the cryptographic random source provided by your operating system. That is the important difference from Math.random, whose output is reproducible and must never be used for passwords.
Can I generate several passwords at once?
Yes. Raise the count field to produce a batch in one go - useful when issuing initial passwords for a list of accounts - then copy the whole block of results.
What is a UUID v4 used for?
A UUID v4 is a randomly generated 128-bit identifier defined by RFC 4122, commonly used as a database primary key, order reference or file identifier - anywhere you need uniqueness without asking a central server for it.
Can I use these for production secrets?
Yes, the random source is cryptographic and the value never leaves your machine. That said, for critical systems the stricter practice is still to generate the secret on the target server or inside a secrets manager, so it never passes through a clipboard.
Related tools
Other tools people use alongside the generator:
Content Breaking
Convert text into Unicode characters that look almost identical to ordinary letters, for captions, bios and headings. Converts as you type, one-click copy, free.
Pixel Mirror
Enter a URL, pick the pages you want and download static HTML, CSS and JS that runs offline. Two modes: Full uses a real browser, Lite is HTTP only.
Image to SVG
Convert PNG, JPG and WebP into SVG vectors in your browser. Tune colours and smoothing with a live preview. Your image is never uploaded.
Random Picker
Draw a random name from your own list or a random number from any range, with an optional no-repeat mode. Your list is stored in the browser. Free, no sign-up.
Change WordPress Host
Enter the old and new domain and get the SQL that updates wp_options, wp_posts and wp_postmeta. For moving WordPress to a new domain or from localhost to hosting.