Create strong random passwords or easy-to-type passphrases, with a strength meter.
20
About this tool
Generate a random password of 8 to 128 characters, or a passphrase of 4 to 8 words from the EFF long wordlist. Values are created in your browser with its secure random number generator, and the strength meter shows the exact entropy in bits and how long an offline attack would take. Nothing is saved or sent anywhere.
Runs in your browser — nothing is uploaded; your input never leaves your device. How it works
Quick answer
Tabreon creates a strong random password, or an easy-to-type passphrase, as soon as the page loads, using your browser's secure random number generator. Choose the length and character types, check the strength in bits and the estimated crack time, and copy it in one click. Nothing is stored or sent anywhere.
Why use Tabreon for this?
Generated on your device with the Web Crypto random number generator, never on a server.
Real entropy figures based on how the password was made, not guesswork from its pattern.
Passphrases from the EFF long wordlist are easier to type and remember.
No sign-up, nothing saved, and nothing you generate is tracked.
How to generate a strong password
1Choose a type. Pick Password for random characters or Passphrase for a string of random words.
2Adjust the settings. Set the length and character types, or the number of words and separator. A new value is generated as you change them.
3Copy it. Check the strength meter, then click the copy button and paste the password into your password manager.
What is password entropy?
Entropy measures how hard a password is to guess, in bits. Each extra bit doubles the number of guesses an attacker needs. A 20-character password drawn from 89 characters has about 129 bits, and a five-word passphrase from a 7,776-word list has about 64. Because Tabreon knows exactly how each value was generated, the figure is calculated, not estimated from how the password looks.
How Tabreon handles your data
Passwords are generated in your browser with crypto.getRandomValues, the same secure random source browsers use for encryption, with rejection sampling so no character is more likely than another. Nothing you generate is stored, logged or sent.
Key features
Passwords from 8 to 128 characters
Uppercase, lowercase, numbers and symbols, with at least one of each chosen type
Option to exclude look-alike characters such as 0 and O
Passphrases of 4 to 8 words from the EFF long wordlist
Strength meter with entropy in bits and an estimated crack time
Generate 5 at once
Common use cases
Creating a new password for an online account to save in your password manager
Making a memorable passphrase for a password manager master password or a Wi-Fi network
Generating several passwords at once when setting up new accounts
Common mistakes & limitations
It does not check passwords you already use.
Generated values are not saved. Copy each one into your password manager before leaving the page.
The crack time assumes an offline attack at one trillion guesses per second. Attacks on online logins are far slower; a leak of weakly hashed passwords can be faster.
Frequently asked questions
For accounts stored in a password manager, 16 to 20 random characters is plenty: that is over 100 bits of entropy, far beyond what any attacker can guess. For anything you need to type or remember, use a passphrase of 5 or more words.
Both are strong when they are random. A random password packs more strength into fewer characters; a passphrase is easier to read, type and remember. Six random words give about 77 bits, the same as a 12-character random password.
Yes. Tabreon uses your browser's crypto.getRandomValues, a cryptographically secure random number generator, and never falls back to weaker randomness. The password is created on your device and never sent anywhere. To hash a password or other text, use the Hash Generator in the developer tools.
No. Nothing is saved in your browser, added to the page address or sent to Tabreon. Reloading the page creates new values and the old ones are gone.
It is the number of bits of randomness, and each extra bit doubles the guesses needed. Under 50 bits is weak, 50 to 69 is fair, 70 to 99 is strong and 100 or more is very strong. The crack time assumes an offline attacker trying one trillion guesses per second.