High entropy
Entropy is the number of bits of unpredictability. An 8-character lowercase password has ~37 bits; a 16-character mixed password has ~95 bits. Every bit doubles brute-force cost. Target ≥80 bits for accounts worth protecting.
Tools · Password Generator
A free, cryptographically secure password and passphrase generator. Uses the
Web Crypto API (crypto.getRandomValues) - everything runs on your device.
Nothing is ever sent to a server.
Generated locally with crypto.getRandomValues. No network, no logging, no telemetry.
Entropy is the number of bits of unpredictability. An 8-character lowercase password has ~37 bits; a 16-character mixed password has ~95 bits. Every bit doubles brute-force cost. Target ≥80 bits for accounts worth protecting.
Reused passwords turn a single breach into a cascade via credential stuffing. Generate a new random password for every account and store them in a password manager like Apex.
Human-chosen passwords cluster around predictable patterns. A CSPRNG (like crypto.getRandomValues) produces uniformly distributed bytes that resist dictionary and pattern attacks.
Yes. Passwords are generated locally in your browser using the Web Crypto API (crypto.getRandomValues), which is a cryptographically secure pseudo-random number generator. Nothing is sent to any server - open DevTools to verify.
For most accounts, 16+ characters with mixed case, digits, and symbols is strong (≥95 bits of entropy). For high-value accounts (email, bank, password manager master password), use 20+ characters or a 6+ word passphrase.
A passphrase is a sequence of random words (like "correct-horse-battery-staple"). They are easier to remember and type than random character strings while providing equivalent or greater entropy. Apex uses an EFF-based short wordlist (1,193 words ≈ 10.2 bits of entropy per word).
No. This page does not store anything server-side. History is kept only in your browser tab memory and cleared on refresh. The Apex password manager app stores your vault encrypted on-device.
Entropy measures the unpredictability of a password in bits. Each added bit doubles the number of guesses required to brute-force. 80 bits is considered strong against offline attacks in 2026; 128 bits is overkill and safe for decades.
Yes. Once the page has loaded, generation works fully offline — no network requests are made to produce a password, and nothing you generate is sent anywhere. (The page itself loads web fonts from a CDN on first visit; you can save it locally to avoid even that.)
Ready for the full vault?
Apex Password stores every credential end-to-end encrypted, on your device. The relay never sees plaintext.