Free security tool
Strong Password Generator
Generate random, unique passwords
Create long, random passwords that are unique to every account in one click. You choose the length and character types.
Strength: Very strongabout 128.9 bits of entropy · pool of 87 characters
Strength is estimated for randomly generated passwords as length × log₂(character pool); it is not a guarantee.
The password is generated in your browser with the Web Crypto API; it is never sent to Doruva or stored.
Definition
What makes a password strong?
A strong password is random enough that it can’t be guessed, long enough that it can’t be found by trial and error, and used for one account only. Birthdays, names, sequences like “123456” and dictionary words are easy to guess, even with some letters swapped for symbols.
This tool builds the password with your browser’s cryptographic random number generator (the Web Crypto API, crypto.getRandomValues). Every character is drawn from the chosen pool with equal probability, and each character type you select appears at least once.
Length
Why length matters most
Every extra character multiplies the number of possible passwords by the size of the character pool. That is why length adds more strength than complexity: a 20-character password of letters and digits is far harder to guess than a 10-character one with symbols.
For accounts you keep in a password manager, 16 to 20 characters or more is a good baseline. If a site limits the length, use the longest password it accepts.
Estimated entropy by length
| Length | Estimated entropy | Level |
|---|---|---|
| 8 | ~52 bit | Fair |
| 12 | ~77 bit | Strong |
| 16 | ~103 bit | Very strong |
| 20 | ~129 bit | Very strong |
| 32 | ~206 bit | Very strong |
The values apply to randomly generated passwords only; passwords people choose are much weaker at the same length.
Uniqueness
Why reusing a password is risky
When a site is breached and e-mail and password pairs leak, attackers try the same credentials on other sites with automated tools (credential stuffing). However strong a password is, using it on several accounts means one leak can open all of them.
Create a separate password for every account, and use unique passwords plus two-step verification wherever you can, especially for e-mail, banking and work accounts.
Storage
Use a password manager
You don’t need to memorise dozens of long random passwords. A password manager keeps them in an encrypted vault, fills them in on the right site and makes using a unique password for every new account easy.
Copy the password you generate here straight into your password manager or the account’s password field. Don’t keep passwords in plain text files, e-mails or chat apps.
Method
How the strength meter works
The meter is based on the estimated entropy of a randomly generated password: length × log₂(character pool), assuming the attacker knows the generation rules. The levels:
- Weak
- Below 45 bits: short passwords or a single character type.
- Fair
- 45–59 bits: acceptable for low-risk accounts, but longer is better.
- Strong
- 60–79 bits: a good level for most online accounts.
- Very strong
- 80 bits and above: for important accounts and long-lived passwords.
FAQ
Strong password generator FAQ
Is the generated password saved anywhere?
No. The password is generated only in your browser; it is never sent to Doruva or any other server, is not stored, and is gone when you reload or close the page. Save the passwords you want to keep in your own password manager.
How long should a password be?
For accounts kept in a password manager, at least 16 characters and ideally 20 or more. For the one master password you need to remember, a long passphrase of several random words is also a good choice.
What does excluding look-alike characters do?
Characters such as I, l, 1, O and 0 look alike in some fonts. If you have to type or read the password, this option reduces mistakes; it slightly shrinks the pool, so it lowers strength only a little.
Do I have to use symbols?
No. Symbols enlarge the pool, but length matters more. Some sites don’t accept symbols; in that case turn them off and increase the length.
Should I change my password regularly?
Current guidance (e.g. NIST SP 800-63B) does not recommend forcing periodic changes of a strong, unique password. Change it immediately if you suspect it has leaked or someone else knows it.
Is a “very strong” password unbreakable?
No password comes with an absolute guarantee. The meter shows estimated resistance to guessing attacks; leaks, phishing and malware need other safeguards. Two-step verification is an important extra layer against them.
Where does the randomness come from?
The tool uses the Web Crypto API (crypto.getRandomValues), the browser’s cryptographically secure random number generator. Math.random, which can produce predictable results, is never used, and characters are chosen with equal probability, without bias.
Tools
More free Doruva tools
Check your site’s technical SEO health, its readiness for AI search or the length of your texts with our other free tools.

