OneFreePlace / Your free workspaceBuilt by people, for people.
A ONEFREEPLACE GUIDE

How to generate a strong password and keep it safe

Choose a long unique password, generate it locally, and save it in a trusted password manager.

The safest password for an account is a unique one you never have to invent or remember. A generator helps by making random choices, while a password manager helps you store and retrieve those choices without reusing them.

Generate a password for one account

Open the password generator. Set a length between 12 and 128 characters and select the character groups the destination service permits. A longer password generally leaves an attacker more possibilities to guess. For most services, 20 or more randomly generated characters is a comfortable choice when the site accepts them.

This generator draws random values from the browser’s cryptographic random source. It includes at least one character from every selected group and shuffles the result. It also avoids modulo bias when choosing characters. The password is created in your browser rather than on our server. If the destination service rejects a symbol, adjust the allowed groups and generate a new password instead of repeatedly trimming one by hand.

Save it before you leave

Copy the result into a trusted password manager and label the account clearly. If you are changing a password, check that the service confirms the change before closing the old credential. Do not put a password in a public note, email draft, or screenshot. The generator does not store a recovery copy for you, so leaving the page without saving the password may mean generating a different one.

Use a different password for each service. Reuse lets a password exposed by one service unlock another. Where available, enable an additional sign-in factor or a passkey. These measures protect you in ways password length alone cannot.

What a generator cannot fix

A random password will not protect an account if you type it into a fake login page or share it with someone else. Check the destination website before signing in, keep your devices updated, and use the manager’s autofill only where you expect it. If you believe a password was exposed, change it at the real service and review active sessions.

← All guides