Choose the length and character types to generate a random password. Passwords are created in your browser and never sent anywhere.
Only the contents of the JWT are read. The signature is not verified, so this tool does not prove that a token is genuine.
Enter Unix seconds or milliseconds, ISO 8601, or a date like "2026-09-30 14:30".
Passwords are generated in your browser and are never sent or stored. They disappear when you close the page, so save one in a password manager.
Type text or choose a file. SHA-1, SHA-256, SHA-384 and SHA-512 are computed. The file never leaves your computer.
Yes. The browser's secure random number generator (crypto.getRandomValues) is used, not a predictable method such as Math.random.
No. Passwords are created only on this page, in your browser. They are not sent to a server or stored, and they disappear when you close the page.
Length matters more than the variety of character types. At least 16 characters is recommended for most accounts. Using a different password for every account and keeping them in a password manager is far safer than reusing one strong password everywhere.
It measures how hard a password is to guess. It is roughly the length times the logarithm of the character pool size. A bigger number means a stronger password. The tool shows the value approximately and rates anything above 80 bits as very strong.