Secret Generator
Passwords, passphrases, API keys, encryption keys and UUIDs from your browser’s cryptographic random generator — with the strength in bits.
How to use
- Pick what you need: password, passphrase, key / token or UUID.
- Adjust the length or preset; the strength in bits updates as you go.
- Copy it — the clipboard is cleared after 30 seconds.
At least one character from each ticked set. Symbols skip quotes, backslashes, spaces and brackets, so the password pastes safely into shells and config files.
Result
Made by your browser’s cryptographic random generator (crypto.getRandomValues). Nothing is stored or sent; copies clear from the clipboard after 30 seconds.
Common questions
How long should a password be?
Aim for at least 80 bits of entropy for important accounts: about 14 random characters from all four character sets, or 7 words from the EFF wordlist. The generator shows the bits for every setting.
Are passphrases safer than passwords?
At the same entropy they are equally strong, and much easier to type and remember. Six random words give about 77 bits — good for a password manager’s master password.
How long should an API key or JWT secret be?
At least 32 random bytes (256 bits). For HS256, RFC 7518 requires a key at least as long as the hash output.
Known limitations
- Generated secrets are only as safe as where you put them: store them in a password manager or secret store, not in chat or tickets.
- Strength assumes the attacker knows exactly how the secret was made (the honest way to measure it).
- UUIDs are identifiers, not secrets; v7 reveals when it was created.
- Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works
Related reading on CipherMind
Standards & references
- NIST SP 800-63B — passwords (opens in a new tab)
- EFF Dice-generated passphrases (opens in a new tab)
- RFC 7518 §3.2 — HMAC key size (opens in a new tab)
- RFC 6238 — TOTP (opens in a new tab)
- RFC 9562 — UUIDs (v4, v7) (opens in a new tab)
- MDN — Crypto.getRandomValues() (opens in a new tab)