Password Toolkit
Everything stays on this device
- Password generation and strength checking run entirely in your browser. Nothing you generate or type on this page is ever sent to a server, stored, cached, or logged.
- Generated and checked passwords disappear when you leave or refresh this page -- there is no history and nothing is saved.
- This tool checks against a small set of common patterns and policy rules. It is a decision aid, not a guarantee -- use a password manager for anything you need to remember long term.
Password Generator
Generated entirely in your browser using the Web Crypto API. Never sent, stored, or logged anywhere.
Password Strength Checker
Checked entirely in your browser as you type. Never sent, stored, or logged anywhere.
Enter a password above to see its strength and policy compliance.
Password Comparison Tool
Compare two passwords side by side. Checked entirely in your browser -- never sent, stored, or logged.
Enter both passwords above to compare them.
Password Length Visualizer
Length matters more than most people expect: each extra character multiplies the number of guesses an attacker would need, rather than just adding to it.
At length 16: about 103.6 bits (Very Strong).
- Very Weak
- Weak
- Fair
- Strong
- Very Strong
| Length | Entropy (bits) | Rating |
|---|---|---|
| 4 | 25.9 | Very Weak |
| 8 | 51.8 | Fair |
| 12 | 77.7 | Strong |
| 16 | 103.6 | Very Strong |
| 20 | 129.5 | Very Strong |
| 24 | 155.4 | Very Strong |
| 28 | 181.3 | Very Strong |
| 32 | 207.2 | Very Strong |
| 40 | 259.0 | Very Strong |
| 48 | 310.8 | Very Strong |
| 64 | 414.4 | Very Strong |
Password Policy Playground
Adjust the policy rules below and see how a sample password fares against them, entirely in your browser.
Enter a sample password above to evaluate it against this policy.
Password Best Practices
- Prefer length over complexity. Each extra character multiplies the number of guesses an attacker needs far more than swapping in one more symbol does -- see the Length Visualizer above.
- Use a different password for every account. Reusing a password means one leaked service can compromise every other account that shares it.
- Avoid dictionary words, names, dates, and keyboard patterns (like "qwerty" or "12345"). These are the first things automated guessing tools try.
- A password manager can generate and remember unique passwords for you, so you never have to reuse one for convenience.
- Turn on multi-factor authentication wherever it's offered. A strong password helps, but a second factor stops most account takeovers even if a password does leak.
- If a service you use reports a breach, change your password there immediately -- and anywhere else you may have reused it.
This toolkit's default policy requires at least 12 characters and every character type -- a reasonable modern baseline, not a hard security guarantee. See the Policy Playground above to try a stricter or looser policy of your own.