Password Generator

Generate passwords locally using browser cryptographic randomness.

  • Free
  • No signup
  • Runs in your browser
Character sets

How it works

How to use

Choose a length and character sets, then generate a password.

Method

Secure browser randomness fills every selected character class.

Example

Create a 20-character password using letters, numbers, and symbols.

Start with the rules of the account that will receive the password

A generated password is useful only if the destination accepts it. Choose a length from 4 to 128 characters and enable the lowercase, uppercase, number and symbol sets that fit the receiving site's rules.

SnakTool's symbol set is !@#$%^&*()-_=+[]{};:,.?. There is no custom-symbol field in this generator, so a site with a narrower or different allowed set may require another configuration or workflow.

Every selected character class gets a place before the rest are filled

Selecting a character class does more than add it to a pool. SnakTool first draws one random character from every enabled class, which guarantees that each selected class appears at least once in the generated password.

The remaining positions are then filled from the combined alphabet of all enabled classes. This is why a requested length must be at least as large as the number of selected classes: four enabled classes cannot each be represented in a three-character result.

Construction rule
selected sets
     ↓
one random character from each
     ↓
fill remaining positions from combined alphabet
     ↓
shuffle every position

The final shuffle removes the construction order

Guaranteeing one character from each selected class would be a poor construction rule if those required characters always remained in predictable positions. After filling the requested length, SnakTool shuffles the complete character array.

The shuffle itself uses the same secure integer selection used elsewhere in generation. The result therefore preserves the class guarantee without leaving the initial one-per-class picks in a fixed lowercase-uppercase-number-symbol sequence.

The random source is Web Crypto, not Math.random

Password characters and shuffle positions are selected from the browser's cryptographic random source through crypto.getRandomValues(). If that secure browser capability is unavailable, generation fails instead of silently falling back to Math.random().

SnakTool also avoids a simple random-number modulo operation when mapping random values into a requested range. Its secure integer helper rejects values outside a clean divisible range before choosing a position, avoiding modulo bias in character and shuffle selection.

Random selection path
crypto.getRandomValues()
          ↓
secure integer with rejection sampling
          ↓
character or shuffle position

Four characters is an input boundary, not a security target

The generator accepts lengths beginning at four because that is its technical input range. It should not be read as a claim that a four-character password is suitable for protecting an account.

Randomness cannot compensate for an extremely small password space. For a real account, follow the destination's requirements and favor a substantially longer unique password that can be stored reliably, rather than treating the minimum accepted slider value as security guidance.

Length and alphabet size change the space an attacker would have to search

When characters are generated randomly, adding positions increases the number of possible outputs dramatically. Enabling more allowed character classes can expand the alphabet as well, provided the receiving service accepts those characters.

That principle is more useful than attaching one universal crack-time number to a password. Guessing speed depends on the attack setting, the service's defenses and, for stolen password databases, the password-hashing scheme and its cost.

A mixed-looking password can still be predictable when a person invented it

Uppercase letters, digits and symbols do not automatically make a human-created password random. Familiar words with a capital first letter, a year and a final exclamation mark can satisfy several composition rules while still following common guessing patterns.

This generator solves a different problem: it samples from the selected alphabets using cryptographic randomness. The checkboxes define what characters are allowed and guaranteed to appear; they are not a strength score by themselves.

One generated password should belong to one account

A long random password loses an important advantage when the same value is reused across services. If one service exposes that credential, an attacker can try the known password against other accounts without having to guess it from scratch.

Generate a separate value for each account. A password manager can make that practical by storing unique credentials so you do not have to turn a random password back into a memorable, reusable pattern.

Generation ends where password management begins

SnakTool creates a password and displays it for use; it is not an account vault, synchronized password manager or recovery service. Do not assume that a value generated today can be retrieved from this tool later.

Store credentials using your own trusted password-management workflow. On the application side, developers should use an appropriate password-hashing scheme for stored password verifiers rather than treating a fast general-purpose hash or reversible encryption as equivalent password storage.

A password still needs protection after you click Copy

Browser-side cryptographic generation addresses how the password is created, not every way the result can later be exposed. Once displayed or copied, a password can still be observed through a compromised device, software with page or clipboard access, screenshots, clipboard history or someone viewing the screen.

Copy the result only where it is needed and move it into the intended account or password manager. Clearing a visible result cannot erase copies that have already reached another application, the clipboard history or a screenshot.

A strong password and MFA protect different failure paths

A unique random password reduces risks tied to guessing and password reuse, but it does not make every other account defense unnecessary. Multi-factor authentication can add a separate requirement when a service supports it.

Treat the generated password as one credential in the account's security design rather than as a reason to disable other protections. The generator creates the secret; it does not configure MFA, monitor breaches or control how the receiving service authenticates users.

Frequently asked questions about Password Generator

Does every selected character type appear in the generated password?

Yes. SnakTool first selects one character from every enabled class, fills the remaining positions from the combined enabled alphabet, and then shuffles the complete result.

Does SnakTool use Math.random() for passwords?

No. Password generation uses the browser's crypto.getRandomValues() source through SnakTool's secure integer helper. If secure browser randomness is unavailable, the generator returns an error rather than falling back to Math.random().

How does SnakTool generate random passwords?

It selects at least one random character from every enabled class, fills the remaining positions from the combined enabled alphabet, and securely shuffles the complete result.

Can I generate a 128-character password?

Yes. 128 characters is the current maximum accepted by SnakTool, although the website or application receiving the password may impose a lower maximum.

Can I generate a numeric password?

Yes. Selecting only Numbers produces a password from digits 0 through 9. Remember that a smaller alphabet reduces the possible-output space for a given length.

Why does SnakTool use rejection sampling for random selection?

A direct modulo mapping can make some outcomes slightly more likely when the random source range is not evenly divisible by the target range. SnakTool rejects the excess range before mapping values so character and shuffle choices avoid that modulo bias.

Why is a random password different from one I invent myself?

People often choose words, dates, substitutions and repeated structures that password guessing can prioritize. A cryptographically generated value is sampled from the configured character space rather than built from a human memory pattern.

Does SnakTool save generated passwords for later recovery?

Do not rely on it for that purpose. The Password Generator is not an account-backed vault or recovery service; store the result in your own trusted password-management workflow.

Is SHA-256 alone an appropriate password-storage scheme?

A fast general-purpose hash by itself is not a modern password-storage scheme. Applications should use a purpose-built password-hashing approach with appropriate parameters and salts rather than treating ordinary SHA-256 hashing as equivalent.

Why might a website reject a generated password?

The destination can impose its own minimum or maximum length, allowed symbols, required classes or other password rules. Configure the generator for those rules before creating the credential.

Does changing a password on a fixed schedule automatically make an account safer?

Not necessarily. A change is clearly warranted when a password is exposed, reused or otherwise compromised; routine changes can also encourage predictable patterns. Follow the security policy of the service and replace compromised credentials promptly.

Browse all Generators