Skip to content
Security

120 random passwords for servers, master keys, admin accounts

120 random passwords generated with the Unbiased Random Selection method (OS CSPRNG with rejection sampling). Lengths from 32 down to 10 characters. Click any password to copy it to clipboard.

ASCII format passwords

The most secure: 86-character printable charset, ~6.43 bit/char entropy. A 16-character ASCII password already carries about 103 bits of entropy: at one trillion guesses per second (an offline GPU rig against a fast hash) a brute-force search would take about 140 billion years on average. At 30 characters it climbs to about 193 bits, beyond the reach of any brute-force attack. Use these for critical services: server access, master keys, admin accounts.

Charset: !"#$%&'()*+,-./23456789:;<=>?@ABCDEFGHJKMNPQRSTUVWXYZ[\]^_`abcdefghjkmnpqrstuvwxyz{|}~

32 characters · Very strong (~206 bit)

h/Q5-GZEet98t|vSpuR7(.eq(!HdjXe(

p7~DEV]4px@#G_CcP@c'Wp]na<pAMyTE

mXdsw*Kdz$&UWVv')V&%M[U?X<*N^WWz

pmNgs4B6HEDCx`jp8UX$,hvm;8:Hr@P~

rp`awu;HBF:<=U+Bk7Z^R^^ZRZz.Zq`t

GxF,.x2'DP`yzY6(ZB+hx{Phqg"4psRN

{heu:?[9QZx3;f-~g{#YMcZh'a"%qW?3

~NZ8JU'RWV+'sHepns`:#2>r/__DTT}k

3]e*wXs2EN[yEb%g:<d~_|JH*F}~n>AE

v."DXm8FD*;'|*{v%{[2DVZ9a'vWY,ck

24 characters · Very strong (~154 bit)

ws''sVsW94y)QZEU)@_U#YQK

=ZnX$%sAxetuZRWAA([4?nU_

/Z-ud<A,*r#2nE5t2mG&J7^t

r/@8\./_%.Fe>UT^&&Pvzbae

p@<P&$4h~{Fc69G9gv<3@_Q8

GkD_BdTSQM8X!)AB\^J.Dqxt

ekEaqT?pBzX'}HA'*K*N`$,%

W{!"#&Dn;Tq_fD$>`7NZNvV}

Y!"p*;]|2x?.Q$Q#"h~Y^@c9

_R=@n`d|kB;`YBb5ypVsa=RN

20 characters · Very strong (~129 bit)

uX+^j|NDX"mB'^r%z5q[

JbS`sPmCvP7M+!E_<r34

/z6n.#v**+>Jkh{:@CGr

`#3<ydj6EPGC/Kru4m&^

<`YtaF!8S3p"k#p!KYUE

PV[<Vf,(]sMKsR8XG%D'

ybp&,,;*ewe:7D:3JR+K

V!J'F?kTjSqc(*n-]D!$

V435@:k9Fu`U?SXBv$N=

Y|zJ$99jE5BMG,wyqaCP

16 characters · Strong (~103 bit)

nvfjsMSf[4}d:4py

[zU?~=^}NMNXU#f~

$m9s"c+8^N<k\"@5

#:TBkB]rEJdT@^%v

\N7@Q!T?R:^,^Rg=

Uz8w&esP6"WdZr$'

p$.H,3sT}`HW5y\<

n^Jqd4z?^^*K?uE}

@jP!W\HEWBuW'Nyd

_2n!Wmn&WxhaKQD!

12 characters · Fair (~77 bit)

tAf^C@c?;e:;

2#=v#ZfeUGKe

*]U)Q,]jz;;&

H4=Y^>||[SU9

Nmp=-g`%9";7

]Gn=KhYT/dX%

9VV[B!|A'rgN

CXR%+\6FBX3*

\E"n=J_p^,P!

-gDmarGnXUzj

10 characters · Fair (~64 bit)

*m}@C+=U/Z

CPP?.X45+m

'37bpuP9bY

qP~{Qwy}!#

5qhX(]|&fk

2``GY=!nv~

e+9*X\q]MT

5'x_2x"k\7

wwtP2PMv~$

Z4gp88^c4U

Alphanumeric format passwords

Reduced charset (54 characters): more readable and typable, lower entropy per symbol. OK for services that forbid special characters. For everything else, prefer ASCII above.

Charset: ABCDEFGHJKMNPQRSTUVWXYZabcdefghjkmnpqrstuvwxyz23456789

32 characters · Very strong (~184 bit)

Hxf2VAvFBTsscTST3zC3gQMnd5mXw7mf

JAGkHz755JCGfFcDkY7H3jjAn8SMj6px

4DqG4qP6yWKzczQJDPP9v9CedFbfjazu

q2pjdx2BEr55ssqYQYkJTN6NRpBe2Wvv

qqTBRMjs6K6pXFzJhyD4tT2nvdmFqPRn

fnPfPG5AhncqQFeeM5EaPk4zadskqTMf

9knUsHxMs8SJ4nB9kUJrSuuhp4uJ7zVy

Z6yZCrhFtXJaJb6RgRhrxWZpTm3QaaGn

RjXNYu9Z4sxYdZuKFgXQ3gSXPG7SHVJN

QTzFdWgfawVFFQfDyXBBdeqJrczerdX4

24 characters · Very strong (~138 bit)

CHq97XKraZf8mYT63GkqHrfQ

scPkmcb4j2abnr2pGNvb4nfH

Bqwg39J3BYq6Q8tVfQArgjHc

98AKxJ45Q3uM6AkqRD66X4jz

E3MUQwnxnddfzfJ7ZbHVRSvS

Hsrcz3MgNJ5RMevrktzRyeyJ

pRQ3vXGqA7EwSuTyvPynjrzy

qAd4sEtxzc5Zx2xbsMWkHMN3

BkQKyQhnujAgfUdSkn5JDRcd

sSc3ED9SNrH8XWKhX8SKbKvM

20 characters · Very strong (~115 bit)

dP5vShQDHn9FXUgsdxhj

2RWM6FyWbz8Dk2tZVH7H

QVsZ87QXAruPMhQnqWgV

yvYzd8kKhvNyDHm22qqB

HSwN3RcpBnzytZE5EmrG

4AnkTGbWPPsdkdKgqaXz

YQ97HaV3YbnfyGZ7RkVs

B4UrrzcQQpef4mWwxjxe

VnMBpxqpAsfgpRzjdJzp

ph6GcSQBdtnpWRncPmPh

16 characters · Strong (~92 bit)

Vzeapk4rE8jkRu4v

BZHwhmbDxzrCxhWB

ChQWD62YPaEeMPsg

6TRgBACWS62Hb8bw

fNBQm9GC7gJhqD8C

2bVebGRZT48xbbHg

UwsgHNbng9NMYUyv

js6UAXZDgQaCJqZa

X2PSkDk7XmESeF4z

9VXsHBHfqcG9GsRU

12 characters · Fair (~69 bit)

Eq58Me95xsxE

j5e8rrMX5Mkj

56yvz3DZGr4y

ukmmtA5R2e5V

DhsAUXTnEUTE

wWtkjrdkbtuD

9p7YhQFXdyFU

xs8Qf4ctTrbR

AtUK5HYUZ6sj

eXuCMRnspjJd

10 characters · Weak (~58 bit)

3HaJ7gBxK4

apDabYzGse

skRKrnTS39

vPGwNH8dRQ

YdvxNCtqpq

j2b7Nna7ym

5wAXcCVMRs

UYfwcdMjKF

9b2wNpRcyx

qbfK4cc7d9

Why these passwords are genuinely secure

Generation uses unbiased random sampling via PHP's random_bytes(), which calls into the OS CSPRNG (/dev/urandom on Linux, equivalents on other OSes), with rejection sampling (bit mask, out-of-range values discarded) that avoids the modulo bias many artisan generators get wrong: every character has probability exactly 1/|charset|. On 20 ASCII characters the real entropy is 128 bits. For comparison, a "strong" password picked by a human typically has 30-50 bits of entropy and is brute-forceable in hours on modern GPUs. The passwords served on the page exist only in the HTML sent to your browser: they are not logged, not persisted anywhere, and do not survive page reload.

Frequently asked questions

How long is a truly secure password in 2026?
Personal accounts: at least 16 ASCII characters (roughly 100 bits of entropy). SSH servers, API keys, admin accounts: 24-32 characters. The real security factor is total entropy, not character class: a 30-char ASCII password is more secure than a 12-char password with 'mandatory symbols'.
Why don't the passwords contain '0', '1', 'l', 'I', 'O'?
Visual ambiguity. If you have to read or type the password by hand (on mobile, on a serial console, on a remote terminal), lookalike characters cause errors. Excluding 8 chars out of 94 (0, 1 and the letters I/L/O both upper and lower case) only changes per-char entropy by ~0.13 bits, negligible compared to total length.
Are generated passwords logged or sent anywhere?
No. The PHP that generates passwords runs server-side in an isolated process, doesn't log output, doesn't store anywhere. Every page reload produces 120 fresh passwords that only exist in the HTML served to you. HTTPS always.
Is random_bytes() really secure?
Yes. In PHP 8.x random_bytes() reads from the OS CSPRNG (/dev/urandom on Linux, equivalents on other OSes): the same entropy source that backs standard cryptographic tooling, and when no entropy is available it throws an exception instead of returning weak bytes. The generator applies rejection sampling to avoid modulo bias, a critical detail many artisan generators get wrong and which leads to non-uniform character distributions across the charset.
Can I use these passwords for encryption or API keys?
For account and service passwords they are fit for purpose. For cryptographic keys (AES, RSA, ECDSA) no: keys must be generated directly with the crypto library that will use them, in the format and length specific to the algorithm. Using an ASCII password as a crypto key introduces an unnecessary KDF derivation, typically done wrong.
What if I work at a company where passwords are shared in an Excel file?
Very common, very risky, very fixable. Migrating to an enterprise password manager (self-hosted Bitwarden, 1Password Business, Vaultwarden) takes 2-3 days of setup + training. If you want a structured path for your SMB, get in touch: this is one of the areas I work on regularly.

Password hygiene at your company is a mess?

If your SMB still uses shared passwords in Excel, reused credentials across services, or lacks a centralized password manager, the compromise risk is high and measurable. I offer targeted consulting on enterprise password policy, migration to self-hosted password managers (Vaultwarden/Bitwarden), and audit of service credentials in use. 20+ years backend + applied cybersecurity.

Talk to me about password security