The password generator that never leaves your browser
Roll a long, random password right here on the page — from your device’s own cryptographic randomness. No server sees it. There is no server. Defaults follow the current guidance: length over complexity.
Skipping look-alikes drops the easily-confused characters — kind on the eyes when a password has to be copied by hand.
What the guidance actually says
NIS2, the EU’s cybersecurity directive, never names a number — it asks for strong authentication, unique credentials and MFA, and leaves the arithmetic to the standards bodies. The numbers people quote come from these, and for the first time in years they agree: length over complexity, every time.
By account type, the practical translation:
Critical
20–24 chars
Email, banking, your password manager — the keys that reset everything else.
Everyday
16–20 chars
Social media, shopping — excellent security, effortless with a manager.
Low-risk
12–14 chars
Forums and subscriptions; 16 everywhere is simpler still.
And the habits that matter more than any single character:
- Complexity rules are out. Mandatory symbols and capitals herd people into predictable patterns — Password1! — while each extra random character multiplies an attacker’s work.
- Rotation is out. Change a password on evidence of compromise, not on a 90-day schedule.
- Breach screening is in. Services should refuse passwords already seen in known leaks; a random roll can’t be one of them.
- One password per account, kept by a password manager — uniqueness beats cleverness.
- MFA wherever it’s offered. A long password is still one factor.
Sources: ENISA NIS2 guidance · NIST · CCB Safeonweb · NCSC-NL · Regulation (EU) 2024/2690. Current to October 2026.
Nothing leaves this page
A password tool gets to see your secrets, so it had better be quiet about them. This one is:
- Every roll comes from crypto.getRandomValues — your browser’s cryptographic randomness, never Math.random.
- Zero requests of any kind. No server, no analytics, no cookies, not even a webfont — the page is one file and loads nothing else.
- No password is ever stored. Each roll lives only in memory, overwriting the last; close the tab and it is gone.
- Your settings are remembered — length and character sets — in your browser’s own local storage, so the page opens the way you left it. That is the only thing ever stored, it stays on your device, and clearing this site’s data removes it.
- Works offline — once loaded, you can regenerate in aeroplane mode.
- The copy button writes to your clipboard locally and tells no one.
Don’t take our word for it: right-click the page and choose View page source (Ctrl+U on Windows and Linux, Cmd+Option+U on a Mac) — it’s a single HTML file with everything in plain sight — or open your browser’s network tab and roll a few. Nothing moves.