A password generator draws characters from sets you choose. This password generator honors those sets. If you tick uppercase, lowercase, numbers, and symbols, the result contains at least one character from each set. The rest of the length is filled from the combined pool. The order is then shuffled with the same cryptographic source. Ticking a set and still getting a letters-only string is the usual silent failure. This page will not do that.
Randomness comes from crypto.getRandomValues, not Math.random. Math.random is fine for a shuffle in a game. It is the wrong API for a secret. If the browser cannot provide Web Crypto, generation stops. The value never leaves the tab. It is not posted, not written to local storage, and not logged by this tool.
This is not a password manager and not a strength oracle. It will not claim the result is unbreakable. Length and character-set variety help. Site rules, reuse, and phishing still matter. For a uniform token without the “one of each class” rule, use the Random String Generator.
If the length is smaller than the number of ticked sets, the status asks for a longer length so each set can appear once. Empty length and non-numeric text are errors. Enter generates from the length field. Labels sit above the controls.
Length 16 with all four sets produces a 16-character string that includes A–Z, a–z, 0–9, and at least one symbol from !@#$%^&*()-_=+[]{}:,.?. Generate again and the value changes. Turning symbols off removes that set from both the guarantee and the pool. HTML-looking text in the length field is rejected as not a number.
Copy the value into the account you are creating, then clear the field if other people can see the screen. Do not paste the same generated password into a chat log “to save it.” That undoes the point of generating it locally.
Some sites reject a subset of symbols. If a form refuses one character, untick symbols or generate again. This page will not probe the remote site. It also will not hash the password for storage. Hashing a password is a server job with a slow password hash, not a SHA-256 of the string you just made.
Look-alike characters such as 0 and O can appear because they are in the sets. That is honest. Filtering them would shrink the pool. If a font on a login form makes them hard to read, generate again or raise the length.
Sixteen characters with four classes is a reasonable default for a new account that accepts symbols. A bank or an admin console that wants 20 or 24 is asking for more length, not a different generator. Raise the number. Do not concatenate two results by hand unless you know why. Two independent draws are not the same as one longer draw from the same pool, but they are also not a documented scheme on this page. Prefer one click at the length you need.
Uses crypto.getRandomValues. Each selected set appears at least once. Not stored, not uploaded, and not a password manager.
It uses crypto.getRandomValues. If that API is missing, the page refuses to generate.
Yes. Each ticked set contributes at least one character before the remaining length is filled.
No. It exists in this tab until you copy it or clear it.
No. The page will not say that. Length and variety help; they are not a guarantee.