Secret Generator

Passwords, passphrases, API keys, encryption keys and UUIDs from your browser’s cryptographic random generator — with the strength in bits.

Runs entirely in your browser. Your browser blocks this page from opening connections or loading anything from other sites. Nothing you enter is uploaded or saved.

requests since opened: 0
How to verify this yourself
  1. Open your browser’s developer tools (F12, or ⌥⌘I on Mac) → Network tab, then use the tool. No new requests appear.
  2. Or disconnect from the internet after the page loads — the tool keeps working, because it never needed the network.
  3. See the rule itself: in the Network tab, select this page’s document → Response Headers → content-security-policy contains connect-src 'none' and no 'unsafe-inline' for scripts.
  4. Press Test the lock: the page tries a harmless request and the browser blocks it (the Console shows the refusal).
How to use
  1. Pick what you need: password, passphrase, key / token or UUID.
  2. Adjust the length or preset; the strength in bits updates as you go.
  3. Copy it — the clipboard is cleared after 30 seconds.

At least one character from each ticked set. Symbols skip quotes, backslashes, spaces and brackets, so the password pastes safely into shells and config files.

≈ 125 bitsvery strong

Result

    Made by your browser’s cryptographic random generator (crypto.getRandomValues). Nothing is stored or sent; copies clear from the clipboard after 30 seconds.

    Common questions

    How long should a password be?

    Aim for at least 80 bits of entropy for important accounts: about 14 random characters from all four character sets, or 7 words from the EFF wordlist. The generator shows the bits for every setting.

    Are passphrases safer than passwords?

    At the same entropy they are equally strong, and much easier to type and remember. Six random words give about 77 bits — good for a password manager’s master password.

    How long should an API key or JWT secret be?

    At least 32 random bytes (256 bits). For HS256, RFC 7518 requires a key at least as long as the hash output.

    Known limitations

    • Generated secrets are only as safe as where you put them: store them in a password manager or secret store, not in chat or tickets.
    • Strength assumes the attacker knows exactly how the secret was made (the honest way to measure it).
    • UUIDs are identifiers, not secrets; v7 reveals when it was created.
    • Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works

    tools v0.9.0 · build 7317bbb · 2026-10-07