Secure Password Generator

Generate strong random passwords instantly. All processing happens in your browser.

Generate a password

๐Ÿ“– How to Use

1
Set Password Length

Drag the slider to set the password length between 4 and 64 characters.

2
Select Character Types

Check which character types to include: uppercase, lowercase, numbers, and/or symbols.

3
Generate and Copy

Click ๐ŸŽฒ Generate to create a password, check the strength indicator, then click ๐Ÿ“‹ Copy to save.

๐Ÿ’ก Tip: Use 12+ characters with all character types for maximum security. Passwords are generated locally and never sent to any server.

About the Password Generator

A password generator produces high-entropy strings that are impractical to guess — unlike the patterns humans tend to invent (names, dates, keyboard walks). This tool builds them in your browser from a charset you choose: uppercase AZ, lowercase az, digits 09, and a pool of symbols. Because every step runs client-side, the value is never transmitted, logged, or stored on a server.

How it works

Each character is drawn from the chosen charset using a cryptographically secure pseudo-random number generator (CSPRNG). In the browser that means the Web Crypto API function crypto.getRandomValues(), which returns unbiased random bytes from the operating system's entropy pool. A naive approach like Math.floor(Math.random() * charset.length) is unsafe for two reasons: Math.random() is a non-cryptographic PRNG whose output can be predicted, and taking a random value modulo the charset length introduces modulo bias when 2^32 is not evenly divisible by the charset size. This tool avoids both by drawing uniform random values and rejecting any that would skew the distribution before mapping an index onto the charset.

The strength of a password is measured in entropy, computed as log2(charset^length) bits — equivalently length × log2(charsetSize). NIST SP 800-63B is clear: prefer length over forced complexity, set a minimum of 8 characters, and do not mandate rotation. Every extra character multiplies the search space by the charset size, so length scales strength exponentially while adding a symbol type only multiplies it once.

Common use cases

  • A unique, strong password for each account in a password manager
  • API keys, shared secrets, or bearer tokens
  • A master password you only memorize once
  • Resetting a compromised credential to an unguessable value
  • A Wi-Fi or database password that is machine-typed rarely

Worked example

A 16-character password drawn from a 94-character printable-ASCII set has:

charset size  = 94  (A-Z, a-z, 0-9, 32 symbols)
length        = 16
entropy       = 16 * log2(94)
              = 16 * 6.55
              โ‰ˆ 105 bits

About 105 bits of entropy. At a billion guesses per second, exhausting that space would take vastly longer than the age of the universe — which is why length from a CSPRNG beats any human pattern.

Frequently asked questions

Are these passwords generated on a server?

No. Passwords are generated entirely in your browser using the Web Crypto API (crypto.getRandomValues). The value never travels over the network or touches a server, so it cannot be intercepted or logged.

How much entropy does a generated password have?

Entropy is log2 of charset size raised to the length, so it equals log2(charsetLength) bits per character. A 16-character password drawn from a 94-character set gives about 16 × 6.55 ≈ 105 bits of entropy, which is far beyond brute-force reach for any realistic attacker.

Why is length more important than special characters?

NIST SP 800-63B advises prioritizing length over imposed complexity. Each added character multiplies the search space by the charset size, while adding one symbol type only multiplies it once. A long password of random words is both easier to remember and harder to crack than a short complex one.

Is Math.random() used to pick characters?

No. Math.random() is a non-cryptographic PRNG and is predictable enough that it must not be used for security. This tool samples with crypto.getRandomValues, a CSPRNG that produces unbiased, unpredictable bytes, and rejects values that would introduce modulo bias.

What is the recommended minimum length?

At least 8 characters is the minimum, but 12 to 16 is recommended for any account that matters. Pair generated passwords with a password manager so you never need to reuse or memorize them.

๋น„๋ฐ€๋ฒˆํ˜ธ ์ƒ์„ฑ๊ธฐ๋ž€?

๋น„๋ฐ€๋ฒˆํ˜ธ ์ƒ์„ฑ๊ธฐ๋Š” ์ถ”์ธก์ด ์‚ฌ์‹ค์ƒ ๋ถˆ๊ฐ€๋Šฅํ•œ ๊ณ ์—”ํŠธ๋กœํ”ผ ๋ฌด์ž‘์œ„ ๋ฌธ์ž์—ด์„ ๋งŒ๋“ค์–ด ๋ƒ…๋‹ˆ๋‹ค. ์‚ฌ๋žŒ์ด ํ”ํžˆ ์ง€์–ด๋‚ด๋Š” ํŒจํ„ด(์ด๋ฆ„, ๋‚ ์งœ, ํ‚ค๋ณด๋“œ ์—ฐ์† ๋ˆ„๋ฆ„)๊ณผ๋Š” ์ •๋ฐ˜๋Œ€์ž…๋‹ˆ๋‹ค. ์ด ๋„๊ตฌ๋Š” ์‚ฌ์šฉ์ž๊ฐ€ ์„ ํƒํ•œ ๋ฌธ์ž ์ง‘ํ•ฉ — ๋Œ€๋ฌธ์ž AZ, ์†Œ๋ฌธ์ž az, ์ˆซ์ž 09, ๊ทธ๋ฆฌ๊ณ  ๊ธฐํ˜ธ ๋ชจ์Œ — ์œผ๋กœ๋ถ€ํ„ฐ ๋ธŒ๋ผ์šฐ์ € ์•ˆ์—์„œ๋งŒ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค. ๋ชจ๋“  ๋‹จ๊ณ„๊ฐ€ ํด๋ผ์ด์–ธํŠธ์—์„œ ์‹คํ–‰๋˜๋ฏ€๋กœ ์ƒ์„ฑ๋œ ๊ฐ’์€ ์ „์†ก๋˜๊ฑฐ๋‚˜ ๋กœ๊น…๋˜๊ฑฐ๋‚˜ ์„œ๋ฒ„์— ์ €์žฅ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

์ž‘๋™ ๋ฐฉ์‹

๊ฐ ๋ฌธ์ž๋Š” ์•”ํ˜ธํ•™์ ์œผ๋กœ ์•ˆ์ „ํ•œ ์˜์‚ฌ๋‚œ์ˆ˜ ์ƒ์„ฑ๊ธฐ(CSPRNG)๋กœ ์„ ํƒํ•œ ๋ฌธ์ž ์ง‘ํ•ฉ์—์„œ ๋ฝ‘์Šต๋‹ˆ๋‹ค. ๋ธŒ๋ผ์šฐ์ €์—์„œ๋Š” Web Crypto API์˜ crypto.getRandomValues() ํ•จ์ˆ˜๊ฐ€ ํ•ด๋‹นํ•˜๋ฉฐ, ์šด์˜์ฒด์ œ์˜ ์—”ํŠธ๋กœํ”ผ ํ’€์—์„œ ๊ฐ€์ ธ์˜จ ํŽธํ–ฅ ์—†๋Š” ๋ฌด์ž‘์œ„ ๋ฐ”์ดํŠธ๋ฅผ ๋ฐ˜ํ™˜ํ•ฉ๋‹ˆ๋‹ค. Math.floor(Math.random() * charset.length) ๊ฐ™์€ ๋‹จ์ˆœํ•œ ๋ฐฉ์‹์€ ๋‘ ๊ฐ€์ง€ ์ด์œ ๋กœ ์•ˆ์ „ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. Math.random()์€ ์ถœ๋ ฅ์„ ์˜ˆ์ธกํ•  ์ˆ˜ ์žˆ๋Š” ๋น„์•”ํ˜ธํ•™์  PRNG์ด๊ณ , ๋ฌด์ž‘์œ„ ๊ฐ’์— ๋ฌธ์ž ์ง‘ํ•ฉ ๊ธธ์ด์˜ ๋‚˜๋จธ์ง€ ์—ฐ์‚ฐ์„ ์ทจํ•˜๋ฉด 2^32๊ฐ€ ๋ฌธ์ž ์ง‘ํ•ฉ ํฌ๊ธฐ๋กœ ๊น”๋”ํžˆ ๋‚˜๋ˆ„์–ด ๋–จ์–ด์ง€์ง€ ์•Š์„ ๋•Œ ๋ชจ๋“ˆ๋กœ ํŽธํ–ฅ(modulo bias)์ด ์ƒ๊น๋‹ˆ๋‹ค. ์ด ๋„๊ตฌ๋Š” ๋‘ ๋ฌธ์ œ๋ฅผ ๋ชจ๋‘ ํ”ผํ•˜ ์œ„ํ•ด ๊ท ์ผํ•œ ๋ฌด์ž‘์œ„ ๊ฐ’์„ ๋ฝ‘๊ณ , ๋ถ„ํฌ๋ฅผ ์™œ๊ณกํ•  ๊ฐ’์„ ๊ฑฐ๋ถ€ํ•œ ๋’ค ์ธ๋ฑ์Šค๋ฅผ ๋ฌธ์ž ์ง‘ํ•ฉ์— ๋งคํ•‘ํ•ฉ๋‹ˆ๋‹ค.

๋น„๋ฐ€๋ฒˆํ˜ธ์˜ ๊ฐ•๋„๋Š” ์—”ํŠธ๋กœํ”ผ๋กœ ์ธก์ •ํ•˜๋ฉฐ, log2(charset^length) ๋น„ํŠธ — ์ฆ‰ length × log2(charsetSize)๋กœ ๊ณ„์‚ฐํ•ฉ๋‹ˆ๋‹ค. NIST SP 800-63B์˜ ๊ถŒ๊ณ ๋Š” ๋ช…ํ™•ํ•ฉ๋‹ˆ๋‹ค. ๊ฐ•์ œ๋œ ๋ณต์žก๋„๋ณด๋‹ค ๊ธธ์ด๋ฅผ ์šฐ์„ ํ•˜๊ณ , ์ตœ์†Œ 8์ž๋ฆฌ๋ฅผ ์„ค์ •ํ•˜๋ฉฐ, ์ฃผ๊ธฐ์  ๋ณ€๊ฒฝ์„ ๊ฐ•์ œํ•˜์ง€ ๋งˆ์„ธ์š”. ๋ฌธ์ž๊ฐ€ ํ•˜๋‚˜ ๋Š˜ ๋•Œ๋งˆ๋‹ค ํƒ์ƒ‰ ๊ณต๊ฐ„์ด ๋ฌธ์ž ์ง‘ํ•ฉ ํฌ๊ธฐ๋งŒํผ ๊ณฑํ•ด์ง€๋ฏ€๋กœ, ๊ธธ์ด๋Š” ๊ฐ•๋„๋ฅผ ์ง€์ˆ˜์ ์œผ๋กœ ์˜ฌ๋ฆฌ๋Š” ๋ฐ˜๋ฉด ๊ธฐํ˜ธ ์œ ํ˜•์„ ํ•˜๋‚˜ ์ถ”๊ฐ€ํ•˜๋Š” ๊ฒƒ์€ ํ•œ ๋ฒˆ๋งŒ ๊ณฑํ•ฉ๋‹ˆ๋‹ค.

์ž์ฃผ ์“ฐ๋Š” ๊ฒฝ์šฐ

  • ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ด€๋ฆฌ์ž์—์„œ ๊ณ„์ •๋งˆ๋‹ค ๊ณ ์œ ํ•˜๊ณ  ๊ฐ•๋ ฅํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ ๋งŒ๋“ค๊ธฐ
  • API ํ‚ค, ๊ณต์œ  ๋น„๋ฐ€, Bearer ํ† ํฐ ์ƒ์„ฑ
  • ํ•œ ๋ฒˆ๋งŒ ์™ธ์šฐ๋ฉด ๋˜๋Š” ๋งˆ์Šคํ„ฐ ๋น„๋ฐ€๋ฒˆํ˜ธ ๋งŒ๋“ค๊ธฐ
  • ์œ ์ถœ๋œ ์ž๊ฒฉ์ฆ๋ช…์„ ์•„๋ฌด๋„ ์ถ”์ธก ๋ชป ํ•  ๊ฐ’์œผ๋กœ ์žฌ์„ค์ •
  • ๊ฑฐ์˜ ์ง์ ‘ ์ž…๋ ฅํ•˜์ง€ ์•Š์•„๋„ ๋˜๋Š” Wi-Fi/๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๋น„๋ฐ€๋ฒˆํ˜ธ ์ƒ์„ฑ

์‚ฌ์šฉ ์˜ˆ

์ถœ๋ ฅ ๊ฐ€๋Šฅํ•œ ASCII 94์ข… ๋ฌธ์ž ์ง‘ํ•ฉ์—์„œ ๋ฝ‘์€ 16์ž๋ฆฌ ๋น„๋ฐ€๋ฒˆํ˜ธ์˜ ์—”ํŠธ๋กœํ”ผ:

charset size  = 94  (A-Z, a-z, 0-9, 32 symbols)
length        = 16
entropy       = 16 * log2(94)
              = 16 * 6.55
              โ‰ˆ 105 bits

์•ฝ 105๋น„ํŠธ์˜ ์—”ํŠธ๋กœํ”ผ์ž…๋‹ˆ๋‹ค. ์ดˆ๋‹น 10์–ต ๋ฒˆ ์ถ”์ธกํ•ด๋„ ๊ทธ ๊ณต๊ฐ„์„ ๋ชจ๋‘ ์†Œ์ง„ํ•˜๋Š” ๋ฐ๋Š” ์šฐ์ฃผ์˜ ๋‚˜์ด๋ณด๋‹ค ํ›จ์”ฌ ๋” ์˜ค๋ž˜ ๊ฑธ๋ฆฝ๋‹ˆ๋‹ค. ๊ทธ๋ž˜์„œ CSPRNG๋กœ ๋ฝ‘์€ ๊ธธ์ด๊ฐ€ ์–ด๋–ค ์˜๋ฆฌํ•œ ์ธ๊ฐ„ ํŒจํ„ด๋ณด๋‹ค ๋‚ซ์Šต๋‹ˆ๋‹ค.

์ž์ฃผ ๋ฌป๋Š” ์งˆ๋ฌธ

๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ์„œ๋ฒ„์—์„œ ์ƒ์„ฑ๋˜๋‚˜์š”?

์•„๋‹™๋‹ˆ๋‹ค. ๋น„๋ฐ€๋ฒˆํ˜ธ๋Š” ์ „์ ์œผ๋กœ ๋ธŒ๋ผ์šฐ์ €์—์„œ Web Crypto API(crypto.getRandomValues)๋กœ ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค. ๊ฐ’์ด ๋„คํŠธ์›Œํฌ๋ฅผ ํ†ตํ•ด ์ „์†ก๋˜๊ฑฐ๋‚˜ ์„œ๋ฒ„์— ๋‹ฟ์ง€ ์•Š์œผ๋ฏ€๋กœ ๊ฐ€๋กœ์ฑ„์ด๊ฑฐ๋‚˜ ๋กœ๊น…๋  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

์ƒ์„ฑ๋œ ๋น„๋ฐ€๋ฒˆํ˜ธ์˜ ์—”ํŠธ๋กœํ”ผ๋Š” ์–ผ๋งˆ์ธ๊ฐ€์š”?

์—”ํŠธ๋กœํ”ผ๋Š” ๋ฌธ์ž ์ง‘ํ•ฉ ํฌ๊ธฐ๋ฅผ ๊ธธ์ด๋งŒํผ ๊ฑฐ๋“ญ์ œ๊ณฑํ•œ log2์ด๋ฏ€๋กœ, ๋ฌธ์ž๋‹น log2(charsetLength) ๋น„ํŠธ์ž…๋‹ˆ๋‹ค. 94์ข… ๋ฌธ์ž ์ง‘ํ•ฉ์—์„œ ๋ฝ‘์€ 16์ž๋ฆฌ ๋น„๋ฐ€๋ฒˆํ˜ธ๋Š” ์•ฝ 16 × 6.55 ≈ 105๋น„ํŠธ์˜ ์—”ํŠธ๋กœํ”ผ๋ฅผ ๊ฐ€์ง€๋ฉฐ, ํ˜„์‹ค์ ์ธ ๊ณต๊ฒฉ์ž๊ฐ€ ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž…์œผ๋กœ ๋„๋‹ฌํ•˜๊ธฐ์—๋Š” ์•„๋“ํžˆ ๋ฉ‰๋‹ˆ๋‹ค.

์™œ ํŠน์ˆ˜๋ฌธ์ž๋ณด๋‹ค ๊ธธ์ด๊ฐ€ ๋” ์ค‘์š”ํ•œ๊ฐ€์š”?

NIST SP 800-63B๋Š” ๊ฐ•์ œ๋œ ๋ณต์žก๋„๋ณด๋‹ค ๊ธธ์ด๋ฅผ ์šฐ์„ ํ•˜๋ผ๊ณ  ๊ถŒ๊ณ ํ•ฉ๋‹ˆ๋‹ค. ๋ฌธ์ž๊ฐ€ ํ•˜๋‚˜ ๋Š˜ ๋•Œ๋งˆ๋‹ค ํƒ์ƒ‰ ๊ณต๊ฐ„์ด ๋ฌธ์ž ์ง‘ํ•ฉ ํฌ๊ธฐ๋งŒํผ ๊ณฑํ•ด์ง€์ง€๋งŒ, ๊ธฐํ˜ธ ์œ ํ˜•์„ ํ•˜๋‚˜ ์ถ”๊ฐ€ํ•˜๋ฉด ํ•œ ๋ฒˆ๋งŒ ๊ณฑํ•ด์ง‘๋‹ˆ๋‹ค. ๋ฌด์ž‘์œ„ ๋‹จ์–ด๋กœ ๋œ ๊ธด ๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ์งง๊ณ  ๋ณต์žกํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ณด๋‹ค ๊ธฐ์–ตํ•˜๊ธฐ๋„ ์‰ฝ๊ณ  ๊นจ๊ธฐ๋„ ์–ด๋ ต์Šต๋‹ˆ๋‹ค.

๋ฌธ์ž๋ฅผ ๋ฝ‘์„ ๋•Œ Math.random()์„ ์“ฐ๋‚˜์š”?

์•„๋‹™๋‹ˆ๋‹ค. Math.random()์€ ๋น„์•”ํ˜ธํ•™์  PRNG๋กœ ๋ณด์•ˆ ์šฉ๋„์— ์“ธ ์ˆ˜ ์—†์„ ๋งŒํผ ์˜ˆ์ธก ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ์ด ๋„๊ตฌ๋Š” ํŽธํ–ฅ ์—†๊ณ  ์˜ˆ์ธก ๋ถˆ๊ฐ€๋Šฅํ•œ ๋ฐ”์ดํŠธ๋ฅผ ๋งŒ๋“œ๋Š” CSPRNG์ธ crypto.getRandomValues๋กœ ์ƒ˜ํ”Œ๋งํ•˜๋ฉฐ, ๋ชจ๋“ˆ๋กœ ํŽธํ–ฅ์„ ์œ ๋ฐœํ•  ๊ฐ’์„ ๊ฑฐ๋ถ€ํ•ฉ๋‹ˆ๋‹ค.

๊ถŒ์žฅ ์ตœ์†Œ ๊ธธ์ด๋Š” ์–ด๋–ป๊ฒŒ ๋˜๋‚˜์š”?

์ตœ์†Œ 8์ž๋ฆฌ๊ฐ€ ํ•˜ํ•œ์ด์ง€๋งŒ, ์ค‘์š”ํ•œ ๊ณ„์ •์—๋Š” 12~16์ž๋ฆฌ๋ฅผ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค. ์ƒ์„ฑ๋œ ๋น„๋ฐ€๋ฒˆํ˜ธ๋Š” ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ด€๋ฆฌ์ž์™€ ํ•จ๊ป˜ ์‚ฌ์šฉํ•ด ์žฌ์‚ฌ์šฉํ•˜๊ฑฐ๋‚˜ ์™ธ์šธ ํ•„์š”๊ฐ€ ์—†๋„๋ก ํ•˜์„ธ์š”.