Zitly logo
Zitly
crypto.getRandomValues() · runs in your browser only

A password generator with nowhere for your password to leak

Last updated October 5, 2026

This is a free password generator that creates random passwords, memorable passphrases, and numeric PINs entirely inside your browser, using the same cryptographic random source security software relies on never a server, and never logged anywhere.

  • Any length from 4 to 128 characters, plus a live strength meter
  • A passphrase mode for anything you need to type from memory
  • No account, no limit, nothing ever sent to a server

Password generator tool

Password Generator
Generate cryptographically secure passwords, passphrases, and PINs never sent to any server
—

Password Options

Advanced

Only !@#$%^&*()

Remove i, I, l, 1, O, 0

Bulk Generator

1
100% Local: every password here is generated in your browser with crypto.getRandomValues(). Nothing is sent to a server.

Five steps to a password you can trust

  1. 01

    Pick a length

    Use a preset or drag the slider to anywhere from 4 to 128 characters. 16 is a solid everyday default; go to 20 or more for anything high-value.

  2. 02

    Choose which character types to include

    Uppercase, lowercase, numbers, and symbols are all on by default. Turn on Safe Symbols Only if a site rejects certain special characters.

  3. 03

    Apply exclusions if the site needs them

    Exclude Ambiguous Characters drops lookalikes like i, l, 1, O, and 0. The custom exclusion field removes any specific characters a form won't accept.

  4. 04

    Check the strength meter and crack-time estimate

    Both update as you adjust settings. Aim for Strong or better, with a crack time in the centuries range, before you use the result anywhere important.

  5. 05

    Copy it into a password manager, not a note

    Click Copy, then paste straight into Bitwarden, 1Password, or whichever manager you use. A generated password is only as safe as where it ends up stored.

What actually makes a password strong

Strength comes down to two things: how large the pool of possible characters is, and how unpredictably they're chosen from it. Length and character variety both grow that pool adding symbols to a lowercase-only password roughly multiplies it by 3.5, and every extra character multiplies it again.

Unpredictability is where a lot of generators quietly fail. A tool built on Math.random() produces output that's technically random-looking but mathematically predictable from its seed. This one uses crypto.getRandomValues(), a cryptographically secure source drawn from the operating system's own entropy — the same category of randomness security tools are built on.

How long should your password actually be?

The slider in the tool above covers anything from 4 to 128 characters including 10, 14, or 15 if a site's own rules call for something in between these bands.

8 charactersMinimum onlyStill common on older systems, but an 8-character password is crackable in hours on modern hardware. Use it only where a site enforces a short maximum.
10–12 charactersEveryday baselineA reasonable floor for low-stakes accounts, especially combined with a password manager and unique passwords per site.
14–15 charactersComfortable middle groundA solid choice when a service caps length below 16 but you still want real headroom over the 12-character baseline.
16 charactersRecommended defaultWith all four character types on, 16 characters puts the crack time well into the centuries range against current hardware. This is the sensible default for most accounts.
20+ charactersHigh-value accountsEmail, banking, and your password manager's own master password deserve the extra length it costs you nothing since a manager types it for you anyway.

Random characters or a passphrase which one here

A random password like k#9mXp2@Tz!rLvQw packs the most entropy into the fewest characters, which is exactly right for anything a password manager will type for you you never need to read it, let alone remember it.

A passphrase built from random words, like maple-tiger-ocean-dance, trades some of that density for something you can actually type from memory. Switch to the Passphrase tab above for that mode it's the better fit for a master password or a device login you type by hand several times a day.

How this compares to the generator already built into your tools

Chrome, Bitwarden, LastPass, and most other password managers already include a generator. They're all capable of producing a strong result the difference is mostly about context, not security.

Chrome's built-in generator

Convenient because it's already there when you're filling a form but tied to that one browser and account.

Bitwarden's generator

Lives inside the extension, so it's a natural fit once you're already managing passwords there.

LastPass's generator

Same idea — fine for day-to-day use inside that ecosystem specifically.

This tool is the better fit when you're outside that context entirely setting up a brand-new manager and need its master password first, generating a WiFi password for a router's admin page, or just want a one-off PIN without opening an extension.

Five habits that undo a strong password

Reusing one password across sites

The majority of account takeovers trace back to credential stuffing: a password leaked from one breach, tried automatically against hundreds of other services. A unique password per account turns one leak into one exposed account, not twenty.

Building passwords from personal details

Birthdays, pet names, and addresses are the first guesses in any targeted attempt, and they're often public on social media anyway. A genuinely random password carries no information an attacker could look up.

Picking a short password because it's easier to type

An 8-character password with every character type can fall in hours on current hardware; 16 characters pushes the same attack into centuries. A password manager removes the typing problem entirely, so there's no real trade-off left to make.

Keeping passwords in a notes app or spreadsheet

Plain text is plain text regardless of which app it sits in anyone with access to the device or the file can read it. A password manager encrypts everything behind one master password instead.

Never rotating a password after a known breach

A breach notice is the one moment rotating a password actually matters. Checking a service like Have I Been Pwned occasionally, and changing anything flagged, closes the window an old leaked password stays useful to anyone.

Curious whether an email has turned up in a known breach already? Check it at haveibeenpwned.com .

Tools that pair with a freshly generated password

  • Turn a generated WiFi password into a QR code so guests connect by scanning a printed card instead of being told the password out loud.
  • Securing a new bio link page account? Generate the login password here first, before the account even exists.

Why nothing here ever reaches a server

Plenty of online password generators work by sending a request to a server, which generates the result and sends it back meaning that server could, in principle, log it. This tool never makes that request. Generation happens in your browser tab, your recent history stays in your own browser's local storage, and nothing you generate here is visible to Zitly or anyone else.

Questions about generating passwords here

Randomness, privacy, length, and how this fits next to a password manager.

Is this password generator actually random?+

Yes. Every password comes from the browser's crypto.getRandomValues() API, a cryptographically secure random source the same category of randomness used in security software, not the predictable Math.random() function some sites still rely on.

Do my generated passwords get sent anywhere?+

No. Generation happens entirely in your browser tab. Nothing is transmitted to a server. Your recent history is saved only in your own browser's local storage and can be cleared at any time.

What's a free password generator with no signup is this one?+

Yes. There's no account, no email, and no limit on how many passwords, passphrases, or PINs you generate.

How long should a password actually be?+

16 characters is a sensible default for most accounts when all four character types are enabled. Go to 20 or more for anything high-value, like email or your password manager's master password. Shorter lengths like 8 should only be used where a site enforces a cap.

What's the difference between a random password and a passphrase?+

A random password like k#9mXp2@Tz!rLvQw packs the most entropy into the fewest characters but is hard to type from memory. A passphrase built from random words, like maple-tiger-ocean-dance, is longer but far easier to recall — a better fit for a master password you type by hand regularly.

What does the crack-time estimate actually mean?+

It's the time a GPU cluster making a trillion guesses a second would need to brute-force every possible combination for your password's length and character set. Real attacks usually try dictionaries and known patterns first, so a genuinely random password resists them even better than the raw number suggests.

How is this different from the generator built into Chrome, LastPass, or Bitwarden?+

Those generators are convenient because they're already inside the tool you're using. This one is useful when you need a password outside that context — setting up a new manager, generating a WiFi password, or just not wanting to open an extension for a one-off PIN. All of them can produce strong results; what differs is where the randomness is generated and how easy it is to reach in the moment.

Should I bother with a password manager if I already generate strong passwords?+

Yes. A strong password only helps if you actually use a different one per site, and nobody can memorize dozens of random strings. A manager stores them behind one master password so uniqueness stops depending on your memory.

Generate one now

Takes less time than reading this sentence.

You might also like

(3 related tools)
Browse all 12 tools