Password Generator
Generate one password or a hundred, with a length and character set you choose. Every password contains at least one character from each type you selected, and the result is shuffled without bias using the platform random source. A general-purpose pseudo-random generator is never involved, because a predictable password is not a password.
Sixteen is already beyond brute force for most sites. Longer only helps if the site stores the whole thing.
Useful for a batch import or a set of test accounts.
Removes the lower-case l, the capital I, the digit one, the capital O, the digit zero and the lower-case o. Worth it for anything read aloud or copied by hand.
How password generator works
- Set the length and the alphabetMore character types means a larger alphabet and more bits per character.
- GenerateEach password gets at least one of every type you enabled, then an unbiased shuffle.
- Store it properlyCopy it into your password manager, then clear the box. Furtu does not clear it for you, because that would race with a copy.
What you get
Make strong passwords from the platform’s cryptographic random source. Everything happens inside this page: the file is read by your browser, transformed in memory and handed straight back to you as a download. There is no upload queue, no waiting for a server, and nothing left behind when you close the tab.
Supported formats
This tool works on text you paste or type, so there is no file format to worry about. Nothing you type is sent anywhere.
Limitations, stated up front
- Furtu cannot tell a site’s rules. Some systems cap the length at 64 or 72 characters, and some reject every symbol.
- A generated password is still a shared secret if you put it anywhere shared. A password manager is the storage, not a spreadsheet.
- The text stays in the box until you clear it or reload the page.
Entropy, briefly
The number Furtu reports is length × log2(alphabet size), which is the size of the space an attacker has to search. It assumes every character is equally likely and that the password is used once against a system that stores it properly. A twenty-character password from a 78-symbol alphabet is around 124 bits, which is why length beats complexity symbols: four extra characters add 25 bits, while swapping a letter for a symbol adds less than one.
Frequently asked questions
Why is this safer than a generator built in the language?
Because the general-purpose pseudo-random generator built into JavaScript is a deterministic sequence, and an attacker who has seen enough of its output can recover the state and predict every value after it, which makes the password a matter of when rather than whether. Furtu uses the platform’s cryptographic random source, and discards the values that would otherwise favour the start of the alphabet, so every character is equally likely.
How strong is the password?
Furtu shows the estimate: length multiplied by the base-two logarithm of the alphabet size. Twenty characters from a 78-symbol alphabet is about 124 bits, which is far beyond any realistic search. The real weakness is rarely the password — it is reuse, and a site that stores it badly.
Why does it force one of each character type?
Because a random twenty-character string occasionally comes out as all digits, and a site with a complexity rule will reject that. Furtu draws one character from each selected type first, fills the rest from the whole alphabet, then shuffles so the position of each character reveals nothing about how it was built.
Where should I store these?
In a password manager, one entry per site, never reused. A generated password is only as strong as the storage around it: a spreadsheet or a chat message undoes everything the generator did.
Is my generated password uploaded or sent anywhere?
No, and that is the only acceptable answer for this tool. Passwords are generated from your browser's own random source, so nothing is uploaded: there is no server that has seen it, logged it, or could hand it over.