Password length: 12, 15, 16 or 20 characters?

Use at least 15 random characters, or 20 where the site accepts it. NIST’s current guidelines (SP 800-63B-4) require services to accept 15+ when a password is the only sign-in factor. A random 5–6 word passphrase is a good alternative.

Set a length without changing the job

In the password generator, set Password length to 12, 15, 16 or 20, or another accepted length. Choose the character sets the account allows and generate a new result. If you tick “Include every selected character set”, the password needs at least one position for each set.

The generator chooses characters randomly on this device. A longer result from the same character pool has more possible combinations, but a hand-chosen repeated pattern does not gain that same property just by being long.

Compare like with like

If every position independently has 26 choices, 12 positions allow 26^12 strings and 15 allow 26^15. The ratio is 26^3 = 17,576. This compares possibilities under that precise rule, not seconds to crack a real password.

Requiring every selected character set removes strings that do not meet that condition. Do not treat the simple pool-size formula as an exact estimate for every generator setting.

A passphrase counts words instead of characters

Choose Passphrase to draw independent words from the supplied EFF long word list. Set the number of words and separator. Choosing your own familiar words is a different process from keeping the random draw.

Generated passwords are not saved by this tool. Copying puts the result on the system clipboard, where other software may have access. The strength checker can highlight obvious patterns; it cannot establish that an account is secure or that a password has never leaked.

Use the tools

Find a tool

Search by task. Use ↓ and ↑ to choose, Enter to open.