Kwebby
Hire Us50% off

Password Generator for Strong, Random Passwords

Generate cryptographically random passwords with custom length and character sets. Runs in your browser. Passwords are never sent or stored.

The latest US government guidance on passwords, NIST SP 800-63B-4 (published July 2025), says a service that relies on a password alone must require at least 15 characters. It also tells services to stop forcing symbol mixes and routine password changes. Length and unpredictability do the work.

The Kwebby Password Generator builds that kind of password for you. It creates random passwords up to 128 characters from the character sets you pick, so you can paste a new one into a sign-up form and save it in a password manager.

Key Takeaways

  • Kwebby's Password Generator creates random passwords from 4 to 128 characters, with uppercase, lowercase, numbers and symbols you can switch on or off.
  • Passwords are generated in your browser with the Web Crypto API, and the page's script does not send or store them.
  • NIST SP 800-63B-4 says services using a password alone must require at least 15 characters, and that they should not force character mixes or periodic changes.
  • Use a different generated password for every account and store them in a password manager.
  • A password you must remember is a different job. The UK NCSC suggests three random words for that.
  • A generator makes a strong password. It cannot protect an account that reuses that password elsewhere or has no second factor.

What Is the Kwebby Password Generator?

Kwebby's Password Generator is a free online tool that creates random passwords from the character sets you choose: uppercase letters, lowercase letters, numbers and symbols. You can set the length from 4 to 128 characters and create up to 20 passwords in one click. Generation happens in your browser, and the page's script does not send the results anywhere or save them.

The page needs no account. Set your options, click Generate Passwords and copy one into your sign-up form or password manager.

Key Features and How It Works

Adjustable length, from 4 to 128 characters

The Length slider runs from 4 to 128 and starts at 16. Use 16 or more for any account you care about. The short settings exist for the odd site with a strict limit. A longer password has more possible combinations, and NIST says services should permit passwords of at least 64 characters, so long ones work almost everywhere.

Four character sets

Under Include, tick Uppercase A-Z, Lowercase a-z, Numbers 0-9 and Symbols in any combination. All four start ticked. Many sites still insist on a mix of types, so you may need all four. Others reject certain symbols, so being able to turn Symbols off saves a failed sign-up. The symbol set is !@#$%^&*()_+-=[]{}|;:,.<>?.

Exclude characters

The Exclude characters field starts with 0Ol1I, which removes the digit zero, capital O, lowercase l, the digit one and capital I because they look alike when you read a password from a screen. Clear the field to allow them, or add any character a site refuses.

Several passwords at once

The Quantity slider runs from 1 to 20 and starts at 5. Generate a batch, then pick the one that suits the site. Each password is generated separately and has its own Copy button.

A quick Strength bar

After you generate, a Strength bar rates the first password in the list as Weak, Fair, Good or Strong. It counts length marks at 8, 12 and 16 characters and the presence of uppercase, lowercase, number and symbol characters. Treat it as a quick sanity check, not an analysis. A meter is a hint, not a guarantee.

Randomness from the browser

The page fills each position with a value from crypto.getRandomValues(), the Web Crypto API method that returns cryptographically strong random values. That is the right source for a password, unlike Math.random(). The tool discards random bytes that would favor some characters over others (rejection sampling), so every allowed character has the same chance at each position. The results appear on screen and nowhere else.

Why Strong, Unique Passwords Matter

A strong password is long and random, and a good password habit is one password per account. Length and unpredictability make guessing slow. Uniqueness keeps one leaked password from opening your other accounts.

The newest NIST guidance puts it plainly. In SP 800-63B-4, services must require at least 15 characters when a password is the only factor, and at least 8 when it is paired with another factor. They must not impose composition rules such as "one symbol and one capital", and they must not force periodic changes without evidence of compromise. Services must also compare new passwords against a blocklist of common or leaked ones, and they should allow paste and password managers.

For you, that means a few things. Aim for length first, use randomness instead of cleverness, and change a password when you have a reason, not on a calendar.

How to Use the Password Generator

  1. Set the length. Drag the Length slider between 4 and 128. The default is 16, and 16 or more suits any account you care about.
  2. Choose the character sets. Under Include, tick Uppercase, Lowercase, Numbers and Symbols. Turn a set off only if the site rejects it.
  3. Exclude characters. Keep the default 0Ol1I to avoid look-alikes, or type the characters a site refuses.
  4. Set the quantity. Drag the Quantity slider between 1 and 20. The default is 5.
  5. Click Generate Passwords. The new passwords appear in the result area. If no character set is ticked, or every character is excluded, the tool shows a short message instead.
  6. Copy and store the password. Click Copy next to the one you want, paste it into the sign-up form and save it in your password manager right away.

Best Practices for Password Generation

Use a unique password for every account

Reuse lets one breach spread. If an attacker gets a password from one site, they try it on other sites. A generated password you never reuse stops that.

Store passwords in a password manager

You cannot memorize dozens of 16 character random strings, and you should not try. A manager stores and fills them for you. NIST tells services to allow managers and autofill, so most sites will accept them.

Turn on a second factor

A strong password still can be phished. Two-factor authentication adds a second check, so a stolen password alone does not get an attacker in.

Do not edit a generated password by hand

Swapping a character for something you can remember makes the password more guessable. If you need something memorable, use a different approach (see the FAQs).

Keep generated passwords out of chat, email and notes

Common mistake: pasting a new password into a message to yourself. Messages are stored, synced and searched. Put the password straight into the manager.

For developers: apply the same rules on your own sign-up form

If you build login forms, follow the NIST points above: allow long passwords, allow paste, skip forced character mixes and check against a list of known bad passwords. Hash stored passwords with a purpose-built password hashing function, never plain MD5. If you want help building a secure sign-up flow, Kwebby builds web apps to your spec.

Common Use Cases

  • New account sign-ups. Create a long random password for every new service.
  • Replacing reused passwords. Swap old shared passwords for unique ones.
  • Router and device admin logins. Set a strong password in place of the factory default.
  • Temporary passwords. Create a one-time password for a new team member to change on first login.
  • Test accounts. Give development and staging accounts real-looking credentials, alongside data from the Fake Address Generator.

Related Kwebby Tools

The Calculators & Utilities hub holds the tools that pair with this one:

Frequently Asked Questions (FAQs)

How does a password generator work?

A password generator picks characters at random from the sets you allow until it reaches the length you set. Kwebby's tool uses the Web Crypto API in your browser for the random choices. The result has no pattern for an attacker to guess.

Is it safe to use an online password generator?

It can be, if the generator runs in your browser and sends nothing out. Kwebby's page builds passwords with the Web Crypto API in your browser, and its script does not send or save them. You can check this yourself by opening your browser's developer tools, watching the Network tab and clicking Generate. Avoid generating passwords on a shared computer or while screen sharing.

How long should my password be?

Use 16 characters or more for important accounts. NIST SP 800-63B-4 requires services to demand at least 15 characters when a password is the only factor and to accept at least 64. Longer is better, and a manager means you never type it.

Do I need symbols and numbers in every password?

Not for strength. NIST says services should not impose composition rules, and length and randomness matter more. Some sites still require a mix, so Kwebby's tool lets you switch each set on or off to match the site. All four start ticked.

Should I use a passphrase instead of random characters?

Use random characters for accounts where a manager stores the password. Use a passphrase for the few passwords you must remember, such as a manager's master password. The UK NCSC suggests three random words for those. This tool creates character passwords, not word passphrases.

Is the Kwebby Password Generator free?

Yes. The tool is free and needs no account.

Final Thoughts

A good password is long, random and used once. Kwebby's Password Generator makes that easy: set the length, pick the character sets, generate a batch and save your choice in a password manager.

Create a fresh password for your most important account today, starting with your email, then turn on two-factor authentication. After that, test a sample of an older password with the Password Strength Checker, or browse the full Kwebby tools list.