A worked example, rendered from real sample data. Sign in to run the tool on your own input.
upper + lower + digits + safe-symbols - ambiguous═══ Generated 5 passwords ═══
mWhCwQr$x^wC=G@6&2vb
QjN#vTb9fVG+QxJ4v2@U
%sVwkYM+*tp8knj-GYaW
Wu%R$r7j-jQyciV-k^BX
^Y37xh66nfxagGQcfYNi
═══ How they were built ═══
Source: 68 characters × 20 positions
Character-set expression:
+ upper (26 characters)
+ lower (26 characters)
+ digits (10 characters)
+ safe-symbols (12 characters)
- ambiguous (14 characters)
Constraints: one of every class present
Randomness: Node's crypto.randomInt, a CSPRNG with rejection sampling, so no character is more likely than another.
═══ Strength ═══
Entropy: 121.7 bits per password (strong)
Offline SHA-256 at 10 billion guesses per second: longer than the age of the universe
Offline bcrypt cost 12 at 20 thousand per second: longer than the age of the universe
⚠ Every constraint shrinks the space these passwords are drawn from. The figure above ignores that, so treat it as an upper bound — the loss is under a bit for the options here.
═══ Policy compliance of the first password ═══
✓ NIST SP 800-63B: satisfied
✓ OWASP ASVS 5.0: satisfied
✓ PCI DSS v4.0: satisfied
✓ Windows Active Directory: satisfied
✗ Oracle Database: contains characters this system rejects: ^ = @ &
✓ MySQL validate_password STRONG: satisfied
✗ Cisco IOS: contains character this system rejects: $
✓ AWS IAM console: satisfied
✓ WPA2 pre-shared key: satisfied
═══ Notes ═══
ℹ Generated on our server and sent back over HTTPS. For a password you will actually use, generate it in your password manager instead — nothing that crosses a network is truly yours.
ℹ Named sets you can use in the expression: upper, lower,
…
Character-set algebra, per-position patterns and policy templates, plus a compliance checker. Part of the DevTools Surf developer suite. Browse more tools in the Generators collection.