Password Generator Widget

Add a password generator to your website. Visitors choose the length and character sets and get up to twenty random passwords, made with the browser's cryptographic random generator and shown with an honest entropy figure.

QR & Generators Generator Runs in your browser Free · no ads

Customize your widget

Theme
Auto follows the visitor's light/dark setting.
Style
Attribution on your page
Optional and entirely your choice. The exact line is shown in the code below; it links to the tool with rel="nofollow".
More options
Starting values
Leave blank to use the widget's defaults. Visitors can still change every value.

Live preview

Exactly what your visitors will see

Embed code

<iframe src="https://a2z.tools/embed/w/password-generator" title="Password Generator by A2Z Tools" width="100%" height="660" style="border:0;width:100%" loading="lazy" allow="clipboard-write"></iframe>

A plain iframe. Works everywhere, including site builders that strip scripts. Adjust height if your content needs more room.

Works with

How it works

Every character is picked from the chosen pool with the Web Crypto random generator and rejection sampling, the same method as the A2Z Secure Password Generator, so no character is more likely than another. When "at least one from each set" is on, a password missing a set is thrown away and drawn again; that keeps every acceptable password equally likely, and the entropy shown is the exact figure for that smaller set of passwords rather than the usual length x log2(pool) overestimate. Look-alike characters (I, l, 1, O, 0, o) can be left out for passwords that people must read or type.

Method

  • Index = random 32-bit word mod n, redrawn while the word >= 2^32 - (2^32 mod n) (no modulo bias)
  • Entropy without set rules = length x log2(pool size)
  • Entropy with one-of-each = log2( sum over subsets S of sets: (-1)^|S| x (pool - size(S))^length )
  • Strength words: under 40 bits weak, 40-63 fair, 64-79 strong, 80+ very strong (A2Z's bands, not a standard)
  • Entropy shown to 1 decimal place; symbol set ! # $ % & * + - = ? @ ^ _ ~

Limitations

  • Entropy assumes an attacker knows your settings but not the random draw; it says nothing about how a website stores the password.
  • Passphrases made of dictionary words (diceware style) are not generated.
  • Some sites reject certain symbols or cap length; the widget does not know a site's rules, so adjust the character sets to match.
  • The widget cannot keep passwords for you - copy them into a password manager, because nothing is saved when the page closes.

Where publishers use it

  • IT help-desk and security-awareness pages giving staff a safe way to make a new password
  • Hosting, SaaS and router-setup guides where readers need an admin or Wi-Fi password
  • Cyber-safety lessons in schools showing how length and character sets change entropy
  • Developer blogs offering random secrets for test accounts and configuration files

Questions

Are the passwords really random?

Yes. They come from crypto.getRandomValues, the browser's cryptographically secure generator, with rejection sampling so every allowed character is equally likely. Math.random is never used.

What does the entropy figure mean?

It measures how many guesses an attacker who knows your settings would need: n bits means 2^n equally likely passwords, so each extra bit doubles the work. 80 bits or more is far beyond practical guessing with current hardware; a 16-character password from all four sets has about 99.7 bits.

Does the site keep a copy?

No. Passwords exist only on the page until you close it. They are not sent to A2Z, stored in the browser or placed on the clipboard unless you press Copy.

Why avoid look-alike characters?

Characters such as l, 1 and I are easy to misread when a password is printed or read aloud. Removing them costs a little entropy, which the widget recalculates.

Sources

  1. Web Cryptography API - Crypto.getRandomValues() - W3C . the browser's cryptographically secure random source
  2. NIST SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management - NIST . Aug 2025: passwords used alone must be at least 15 characters (8 with another factor); sites should allow at least 64 and should not impose composition rules

Cite or recommend this tool

If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.

A2Z Tools Password Generator
https://a2z.tools/secure-password-generator

Preview