Back to the tool

Is It Safe to Use an Online Password Generator?

Is it safe to use an online password generator? People ask me this every time they watch me generate a password in a browser instead of inside an app. The short answer is usually yes, if you can verify one thing. The long answer fits in about 60 seconds of checking, and I will show you exactly how.

The fear is sensible. You are asking a website to create the key to your accounts. If that site records what it makes, you just handed your keys to a stranger. So the entire question comes down to one technical detail: does the password get created on your computer, or on their server?

Client side or server side: the only question that matters

A client-side generator runs JavaScript inside your browser. Your machine rolls the dice, your machine shows the result, and nothing crosses the internet. A server-side generator assembles the password on the site owner's machine and sends it to you, which means a copy can sit in their logs whether they intended it or not. You cannot tell the two apart by looking at the page. They look identical. That invisible difference is the whole risk model, and it matters more than the site's reputation or its privacy policy.

How to check an online password generator in 60 seconds

Open the generator. Press F12 to open your browser's developer tools and click the Network tab. Now generate a password. Generate three more. Watch the request list. If generating produces no outgoing requests, nothing left your machine. The generation happened locally, in your browser, on your computer.

That test takes about a minute, and it settles the main question. I run it on any generator I am about to rely on. It is the same check security writers describe, and it works because a client-side generator simply has no reason to talk to a server while it works.

One honest limit, though. The test tells you what the page does right now. Websites get redeployed. A page that was clean last month can ship a change tomorrow. I keep this in mind and treat online generators as convenient rather than sacred. For the one password that unlocks everything else, my password manager master password, I generate it once and I keep it myself. I cannot audit someone's code every day, so I put my permanent secrets somewhere that does not depend on a website staying honest.

The weak-randomness trap most people never check

Local generation is necessary but not sufficient. A client-side generator can still be bad if it uses the wrong random source. JavaScript has Math.random, which is fine for shuffling a playlist and useless for passwords. It is not cryptographically secure, which is a technical way of saying its output is predictable to someone who tries. A real generator uses crypto.getRandomValues from the Web Crypto API, the same engine your browser uses behind the scenes for TLS keys.

You can verify this in the page source. Right-click, view source, search for getRandomValues. If you find Math.random anywhere near the generation code instead, close the tab and pick a different generator. This bug is rarer than the server-side problem, but when it shows up it silently turns every password the site makes into something weaker than it looks.

Do not let an AI chatbot make your passwords

A language model predicts likely text. A password needs every option equally likely. Those are different jobs, so use a generator built for randomness rather than a chatbot built for plausibility.

The verdict I give friends

Use a client-side generator you have checked, or better, the generator built into your password manager, which removes the copy step entirely. Store everything in the manager. Then memorize exactly one secret: a long passphrase for the master password. That arrangement gives you strong unique passwords everywhere and a single memorable one where it counts, and no website in the world needs to see any of them.

Frequently asked questions

Can the website see the password it generated for me?

Only if it generates the password on its server. A client-side generator builds the password inside your own browser with JavaScript, so the site never receives it. Run the network-tab test: if generating produces zero outgoing requests, nothing left your machine.

Is my password manager's generator safer than a website?

Slightly, because the generator lives inside the vault that stores the password, so there is no copy step and no chance of a server-side generator you did not audit. For day to day use I prefer it. For a master password I use a diceware passphrase I generate once, because that one I have to memorize.

Can I ask an AI chatbot to generate my password?

I would not. Language models predict likely text; they do not draw from a uniform random distribution, and they can repeat patterns across users. A password needs true randomness from a cryptographic source, which is not what a chatbot does.

What is the Math.random problem with online generators?

Math.random is JavaScript's general purpose random function, and it is not cryptographically secure: its output can be predicted. A password generator should use crypto.getRandomValues from the Web Crypto API instead. If you see Math.random near the generation code in the page source, stop using that generator.

How can I tell whether a generator I never heard of is trustworthy?

Run the 60 second test: open the network tab, generate several times, confirm zero requests leave your browser, then view the page source and confirm it uses crypto.getRandomValues rather than Math.random. That covers the two failure modes. Beyond that, prefer a generator from a source with a reputation worth protecting.

Related reading: Diceware Passphrase vs Random Password: Which One Should You Actually Use? · How Many Words Does Your Passphrase Need? Entropy Math, Worked Out · The One Passphrase Setup: Why Your Password Manager Deserves a Great Master Secret · How Long Should a Wi-Fi Password Be?

Try the tool

The passphrase generator on this site runs entirely in your browser. Nothing is sent anywhere, and you can verify that with the network-tab test above. Generate a passphrase now and watch devtools while you do it.

Get new free tools by email

Want the next guide in your inbox? I publish one practical guide per new tool. Subscribe to the free newsletter on Substack. No spam, unsubscribe anytime.