Human-Friendly Password Generator
Generate strong, secure passwords that are designed to be easy to read, type, and use.
Your password is generated entirely in your browser using cryptographically secure randomness. Nothing is sent to a server (open your network tab if you want to check).
Why human-friendly?
Strong passwords don't have to look like keyboard noise. There are plenty of generators that spit out a random wall of symbols and call it a day, but I built this one after one too many sites made me type a password by hand instead of pasting it. Easily confused characters like 0/Oor l/1, and symbols scattered everywhere, made that miserable, so this generator leaves ambiguous characters out and caps symbols at 2, never placing two of them next to each other. The result is a password that's friendly to humans without compromising security. Enjoy.
How this generator works
Every character comes from crypto.getRandomValues, the browser's cryptographically secure random number source. Math.random is never used here: it is fast, but it is not designed to resist prediction, and that matters when the output is a password.
Picking a random character from a set of size N with a plain value % N introduces a small bias toward the lower remainders whenever 2^32 is not an exact multiple of N. This tool avoids that by rejecting and redrawing any value that falls outside the largest multiple of N that fits in 32 bits, so every character in the set has an equal chance of being picked.
Independent random draws do not promise that every character type you selected actually shows up. It is entirely possible to ask for digits and get a password with none, purely by chance. After generating the password, this tool checks for that and patches in one character from any selected type that did not appear, at a random position.
Symbols get two extra rules on top of that: no more than 2 in total, and never two next to each other. Whenever either rule would otherwise be broken, that position is drawn only from your other selected character types instead. Combined with the guarantee above, symbols end up appearing exactly 1 or 2 times whenever they are turned on, never 0.