Password generator

Strong, random passwords made on your device. Nothing you generate is ever sent anywhere.

Generating on your device…

Calculating

 

Password options

Include

More options

Useful when a site rejects certain symbols.

What makes a generated password strong

Strength comes from how many passwords your settings could have produced, and that grows fastest with length. Twenty characters from all four character sets give about 131 bits of entropy. Guessing that at three trillion attempts a second would take far longer than the universe has existed.

Use a different password for every account and keep them in a password manager. If a site limits which symbols it accepts, leave those characters out rather than shortening the password.

How SecurePass keeps your passwords to yourself

There is no server that sees your passwords, because there is no server involved at all. Here is what that means in practice, and how you can check each part yourself.

Made by your device, not a server

Every character comes from crypto.getRandomValues, your browser's cryptographically secure random number generator. It is the same source browsers use to create encryption keys.

Turning random numbers into characters is where many generators go wrong. Taking a remainder makes some characters slightly more likely than others. SecurePass throws away any number that would cause that bias, so every possible password is exactly as likely as every other.

If your browser can't provide secure randomness, SecurePass refuses to generate anything rather than fall back to something weaker.

The function every character passes through
export function randomInt(n: number): number {
  if (!Number.isSafeInteger(n) || n < 1 || n > UINT32_RANGE) {
    throw new RangeError(`randomInt needs an integer range between 1 and 2^32, got ${n}`);
  }
  const source = secureSource();
  // 2^32 is rarely a multiple of n, so reducing every draw modulo n would make the low results
  // slightly more likely. Draws at or above the largest multiple of n are discarded and redrawn;
  // even in the worst case under half of all draws are rejected, so the loop ends quickly.
  const limit = Math.floor(UINT32_RANGE / n) * n;
  const draw = new Uint32Array(1);
  for (;;) {
    source.getRandomValues(draw);
    const value = draw[0] ?? limit;
    if (value < limit) return value % n;
  }
}

Nothing is sent, and you can check

SecurePass is a set of static files. Once the page has loaded, generating and checking passwords makes no network requests at all, and the page's security policy would block one if it tried.

The counter beside this text watches every request this page makes to another site. It stays at zero unless you run a breach check.

Verify it yourself

  1. Open your browser's developer tools with F12, or Cmd Option I on a Mac.
  2. Choose the Network tab.
  3. Generate a few passwords and type in the strength checker.
  4. Watch the list stay empty.

To go further, turn on airplane mode. After your first visit SecurePass keeps working, because it runs entirely from your device.

0

requests to other sites since you opened this page

Saves itself for offline use after your first visit.

Locked down by your browser

Every page arrives with a strict Content Security Policy, which your browser enforces. Even if SecurePass's own code had a bug, the browser would refuse to load scripts from anywhere else, send data to an unknown server, or let another site wrap the page in a frame.

This is the exact policy your browser received with this page, and what each rule does.

default-src 'none'
Block everything that is not explicitly allowed below.
script-src 'self' 'sha256-wzSTKVRzhp6995mnNaSiDXEUvxIxwPJxho/of/nQob0='
Run only SecurePass's own scripts, plus one tiny inline script that applies your theme, pinned by its hash.
style-src 'self'
Load styles only from SecurePass. No inline styles.
img-src 'self'
Load images only from SecurePass.
font-src 'self'
Load fonts only from SecurePass. No font CDNs that could log your visit.
connect-src 'self' https://api.pwnedpasswords.com
Allow network requests only to SecurePass and the breach-check service, which is only contacted when you press the button.
manifest-src 'self'
Read the install manifest only from SecurePass.
worker-src 'self'
Run only SecurePass's own offline service worker.
base-uri 'none'
Stop injected markup from redirecting where relative links point.
form-action 'none'
Nothing on the page can submit a form anywhere.
frame-ancestors 'none'
No other site can embed SecurePass in a frame to trick you.
object-src 'none'
No plugins or embedded objects.
upgrade-insecure-requests
Any plain HTTP request is upgraded to HTTPS.
require-trusted-types-for 'script'
The page cannot turn text into code. Every script URL has to pass a reviewed policy.
trusted-types securepass
That policy exists for one job: registering the offline service worker at /sw.js.
The other security headers
Strict-Transport-Security
Browsers must use HTTPS for securepass.dev for the next two years.
Referrer-Policy
Never tell another site which page you came from.
X-Content-Type-Options
Browsers must not guess file types, so a file can't be passed off as a script.
X-Frame-Options
The older form of the frame ban, for browsers that predate frame-ancestors.
Cross-Origin-Opener-Policy
Other windows cannot keep a handle on this page.
Cross-Origin-Embedder-Policy
The page refuses resources from other sites unless they explicitly opt in.
Cross-Origin-Resource-Policy
Other sites cannot load SecurePass's files into their pages.
Permissions-Policy
Camera, microphone, location and 29 other device features are switched off. Only writing to the clipboard is allowed.

Nothing stored, nothing tracked

No accounts, no cookies, no analytics, no ads and no third-party scripts. SecurePass doesn't know who you are or how you use it, and it has no way to find out.

The only thing it remembers is your settings, kept in your browser's local storage so they are there next time. Clearing this site's data removes them.

Remembered on this device

  • Length and character choices
  • Passphrase and PIN settings
  • Light or dark theme

Never kept anywhere

  • Generated passwords
  • Passwords you check
  • Breach check results
  • Your IP address, device or visits

A breach check that never reveals your password

Have I Been Pwned keeps hundreds of millions of real passwords exposed in data breaches. SecurePass can look yours up without sending it, or even its full fingerprint, using a technique called k-anonymity. It only happens when you press the button.

  1. Your device hashes the password with SHA-1.

    password 5BAA61E4C9B93F3F0682250B6CF8331B7EE68FD8

  2. Only the first 5 of its 40 characters are sent.

    api.pwnedpasswords.com/range/5BAA6

  3. The service returns every breached hash starting with those 5, around 800 to 1,000 of them, padded with decoys so even the reply's size gives nothing away.

    0018A45C4D1DEF81644B54AB7F969B88D65:count00D4F6E8FA6EECAD2A3AA415EEC418D38EC:count…1E4C9B93F3F0682250B6CF8331B7EE68FD8:count…

  4. Your device looks for the other 35 characters in that list. The service never learns which one, if any, was yours.

    1E4C9B93F3F0682250B6CF8331B7EE68FD8 found

Breach data: Have I Been Pwned. The request carries no cookies and no referrer, and it is the only request SecurePass's security policy allows to another site.

How crack time is estimated

The headline number assumes a well-equipped attacker, so it never flatters a password.

Generated passwords: exact maths

A generated password's strength is exactly the number of passwords your settings could have produced. SecurePass counts them, leaving out any that would be missing a character type you asked for, and reports the result as bits of entropy. Twenty characters from all four sets give about 131 bits; six passphrase words give about 77.5.

An attacker who knows exactly how the password was made still has to try, on average, half of the possibilities. The time is that number of guesses divided by the attacker's speed.

Passwords you type: pattern analysis

People don't choose characters at random, so length alone says little. The checker uses zxcvbn to find the dictionary words, names, dates, keyboard runs and substitutions that cracking tools try first, and estimates how many guesses those patterns take. Long, patternless runs are priced as random.

Attack speeds used for the estimates
AttackGuesses per secondAssumption
Online, rate-limited100 guesses per hourGuessing through a login page that slows down or locks out repeated attempts. This is zxcvbn's throttled-online assumption. Source
Online, no rate limit1,000 guesses per secondGuessing against a login or API that never slows the attacker down, which OWASP warns against. The service itself becomes the bottleneck. Source
Offline, slow hash100,000 guesses per secondA stolen database protected by a slow password hash (bcrypt, cost 10), attacked with twelve RTX 5090 graphics cards, as in Hive Systems' 2025 password table. Source
Offline, fast hash3 trillion guesses per secondA stolen database protected only by a fast hash such as MD5 or SHA-1, attacked with twelve RTX 5090 cards at about 220 billion MD5 guesses per second each (2.64 trillion in total), rounded up. Source

Ratings

  • Very weakunder 45 bits
  • Weak45 to 59 bits
  • Fair60 to 74 bits
  • Strong75 to 99 bits
  • Excellent100 bits or more

What good password hygiene looks like in 2026

Based on NIST SP 800-63B-4, the US government's digital identity guidelines, finalised in 2025.

  • Length beats complexity

    Use at least 15 characters for any password that is the only thing protecting an account. Mandatory symbol-and-number rules are out; length and randomness are what count.

  • One password per account

    Reused passwords turn one breach into many. A password manager makes unique passwords effortless.

  • Check against breaches

    Services should reject passwords already exposed in breaches, and so should you. A breached password is the first thing attackers try.

  • Change it when there's a reason

    Forced changes every few months are no longer recommended. Change a password when there is any sign it has been exposed.

  • Add a second factor

    Turn on passkeys or two-factor authentication wherever they are offered. They stop a stolen password from being enough on its own.

Questions, answered plainly

Does SecurePass send or store my passwords?
No. Passwords are generated and analysed by code running in your browser, and they are never sent, saved or logged. The page's security policy only allows network requests to SecurePass itself and, if you press the button, the breach-check service. Even then only five characters of a hash leave your device.
How can I check that for myself?
Open your browser's developer tools, choose the Network tab, and use the generator and strength checker. No requests appear. You can also turn on airplane mode after your first visit: SecurePass keeps working because it runs entirely on your device. The network counter on this page shows the same thing live.
Does it work offline?
Yes. After your first visit a service worker keeps a copy of every page, script and wordlist on your device, so SecurePass loads and works without a connection. Only the optional breach check needs the internet.
Is the breach check private?
Yes. It uses k-anonymity: your device hashes the password with SHA-1 and sends only the first five of its forty characters to Have I Been Pwned. The reply lists every breached hash that starts with those characters, padded with decoys, and your device looks for a match itself. See how it works.
What can't SecurePass protect against?
Anything that already has access to your device or screen. A malicious browser extension can read any page you open. Malware can read your keyboard and clipboard. Clipboard history and sync features, such as Windows clipboard history or Apple's Universal Clipboard, may keep or share a copy of anything you copy. And someone looking over your shoulder can read your screen, which is why you can hide the generated password.
Why does the checker rate a long password as weak?
Length only helps if the characters are unpredictable. The strength checker looks for the patterns that cracking tools try first: common passwords, dictionary words, names, dates, keyboard runs like qwerty, repeats and predictable substitutions like @ for a. A long password built from those patterns can fall in seconds.
Should I use a password or a passphrase?
Both are strong when they are random and long enough. A random password packs more strength into fewer characters, which suits a password manager. A passphrase of six or more random words is far easier to type and remember, which suits the few passwords you type by hand, like your password manager's own.
How random is it?
Every character and word comes from crypto.getRandomValues, your browser's cryptographically secure random number generator, the same source browsers use for encryption keys. SecurePass discards any random number that would make some characters more likely than others, so every possible password is equally likely.
Is it really free?
Yes, with no ads, accounts or tracking. SecurePass is a set of static files, which cost nothing to serve, and the source code is open under the MIT license.