PassMaker - Simple Password Generator
PassMaker makes a new random password with a single tap. By default it creates a 12-character password from lowercase and uppercase letters, digits and symbols, shows it on screen and copies it to your clipboard so you can paste it straight into a sign-up form or your password manager.
Most people reuse a handful of passwords because inventing strong new ones is tedious. A generator removes that friction: every account can have its own unrelated password, so a leak from one website doesn't unlock the others. You can also adjust the length and character types to meet a site's rules, or produce a numbers-only code.
Passwords are created inside your browser using its cryptographically secure random number source. PassMaker doesn't store them and doesn't send them anywhere.
The app runs entirely in your browser. What you enter is saved only on this device.
How to use PassMaker
- Generate. Tap Generate Password. A new password appears in large text and is copied to your clipboard automatically.
- Copy again if needed. Tap Copy to put the current password on the clipboard again, for example after you have copied something else.
- Open the settings. Tap the gear button to change how passwords are made.
- Choose length and characters. Drag the length slider anywhere from 4 to 30 characters, and switch uppercase letters, numbers and symbols on or off. Turn on Numbers only for a PIN-style code.
- Save and generate. Tap the check button to apply the settings, then generate a new password.
- Store it safely. Paste the password into the site and into a password manager straight away. PassMaker won't remember it for you.
Features
- One-tap random password generation
- Automatic copy to clipboard
- Length from 4 to 30 characters (12 by default)
- Optional uppercase letters, numbers and symbols
- Numbers-only mode for PIN-style codes
- Uses the browser's cryptographically secure random generator
- Nothing is saved or transmitted
What makes a password strong
Length and randomness beat cleverness
A password's strength comes from how many possibilities an attacker would have to try. That grows with both length and the size of the character set. A 12-character password drawn from about 85 possible characters has roughly 10^23 combinations; adding four more characters multiplies that by around 50 million. Substituting @ for a or adding '1!' to a word adds very little, because attackers' tools try those patterns first.
Randomly generated passwords avoid the patterns humans fall into: names, dates, keyboard walks and favourite words.
Use a different password everywhere
Data breaches happen regularly, and leaked email and password pairs are tried automatically on other sites. This 'credential stuffing' only works when passwords are reused. Giving every account its own random password contains the damage of any single breach. The practical way to manage dozens of unique passwords is a reputable password manager, which can store them and fill them in for you.
Turn on two-step verification
Even a perfect password can be phished. Enabling two-step verification, such as an authenticator app, a security key or a passkey where offered, means a stolen password alone isn't enough. Prioritise your email account, because it can reset most other accounts, along with banking and shopping sites.
PINs and site rules
Some systems only accept digits or impose length limits. A numbers-only code is much weaker than a mixed password of the same length, so use the longest PIN allowed and rely on the system's lockout after failed attempts. If a site rejects certain symbols, switch symbols off and add a few characters of length instead.
When to change a password
Current guidance from security agencies is not to force regular password changes for their own sake, since that pushes people toward predictable variations. Change a password when there is a reason: the service reports a breach, you shared it with someone, you typed it on a device you don't trust, or a breach-notification service shows your email in a leak. When you do change it, generate a completely new one rather than tweaking the old password.
Frequently asked questions
Are my passwords stored or sent anywhere?
No. Each password is generated in your browser and only shown on screen and placed on your clipboard. Nothing is saved by the page or sent to a server. Remember to save it in a password manager.
How random are the passwords?
They use the browser's cryptographically secure random number generator (the Web Crypto API), the same kind of source used for security keys.
Why did the site reject my password?
Some sites limit length or disallow certain symbols. Adjust the length or switch symbols off in settings and generate a new one.
Are my settings remembered?
No. Length and character options reset to the defaults when you reload the page.
What is different from the phone app?
The generator is the same. The iPhone and Android apps show ads that a subscription removes; the web version has no ads or purchases.
Limitations of the web version
- Settings reset when the page is reloaded
- No passphrase (word-based) mode
- Doesn't store passwords; use a password manager
Disclaimer
PassMaker generates random characters only. Keeping your accounts secure also depends on storing passwords safely, not reusing them and enabling two-step verification where available.
Phone app
PassMaker is also available as an app for phones and tablets: