Password Security Toolkit
Generate a strong password, check the strength of one you already have or estimate one hypothetically, define or validate the policy an organization follows, and grade its storage practices. All run entirely in your browser.
How these fit together
Six tools for six different moments in a password's life, not a pipeline you run in order. Password Generator creates a strong, random credential for a new account using the Web Crypto API — the right tool when nothing about the password needs to be memorable. Already have a password and want to know how it actually holds up? Password Entropy Calculator estimates its entropy in bits, translates that into a realistic crack time across several attack scenarios, and checks it against common weak patterns a raw entropy number misses entirely. Planning a length/character-set requirement instead of auditing a real password? Password Cracking Time Estimator runs the same crack-time math from a hypothetical length and charset alone. Zooming out from one password to the rule everyone has to follow, Password Policy Generator turns a set of choices — minimum length, rotation, MFA, breach-checking — into a policy document and checks each one live against NIST SP 800-63B, the standard that reversed a lot of older conventional wisdom about what actually makes a policy stronger. Have an existing policy's text instead of a blank slate? Password Policy Validator runs the same NIST check the other direction — paste free-text policy statements and it recognizes what it can, flags what NIST recommends against, and calls out what the excerpt never mentions at all. None of the five so far look at how a password is actually stored once it's submitted — Password Storage Checker covers that separately: answer a few questions about hashing algorithm, cost parameters, salting, MFA, breach-checking, and rate limiting, and get each graded against OWASP and NIST guidance.
Password Generator
Generate strong, random passwords with custom length and character sets.
Password Entropy Calculator
Estimate a password's entropy, crack time, and common weak patterns.
Password Cracking Time Estimator
Estimate brute-force complexity from a length and character set — no real password needed.
Password Policy Generator
Generate a password policy document and check it against NIST SP 800-63B guidance.
Password Policy Validator
Paste a password policy's text and check it against NIST SP 800-63B guidance.
Password Storage Checker
Answer a few questions about your storage practices and get them graded against OWASP/NIST.
Learn more
- Password Security: A Comprehensive Guide
- What Makes a Strong Password Policy?
- NIST Password Guidelines Explained
- Password Rotation: Good or Bad?
- Multi-Factor Authentication Explained
- Minimum Password Length Recommendations
- Passwords vs Passkeys
- Credential Stuffing Explained
- Credential Rotation
- Password Spraying Explained
- How Long Does It Take To Crack A Password?
- What Happens If Password Hashes Leak?