Secure Password Generator

Generate strong passwords with cryptographic randomness. Customize length, symbols, numbers, and uppercase.

Cryptographic entropy

Uses crypto.getRandomValues — not Math.random — for secure randomness. Every password generated is cryptographically unpredictable and suitable for real accounts.

What makes a password strong?

Length is the single most important factor. A 20-character password mixing letters, numbers, and symbols has more entropy than any common pattern. RookPass generates passwords up to 128 characters.

How this page is different

Secure Password Generator exists to generate a random password or passphrase in the browser and keep it out of a server log. It is not a second copy of the tool homepage. The homepage introduces the whole product. This page stays on one job so a search for that job lands on instructions you can follow without hunting through other tabs. Read the result on this page against the input you actually used. A screenshot without the input is not evidence. If the result surprises you, change one thing and run it again before you change your VPN, browser, or server config.

Do this on the page

Work through Secure Password Generator in order. 1. Choose a length you will actually store in a manager. 2. Include the character sets the site allows. 3. Generate. 4. Save the result in a password manager, not in the chat where you generated it. Write down the input and the output together. When you ask someone for help, send both. Repeat the same input once. A stable tool returns the same answer. If it does not, the input changed or the page is talking to a different network path than you think.

What this page will not decide for you

The page does not remember the password. A password you cannot store will be reused. Generation is not a breach check until you open the HIBP page. Treat the output as a measurement, then decide. RookVPN does not log the contents of a client-side tool, and a measurement is not a promise that every other app on the device behaves the same way. Compare a second path when the decision matters: a terminal command, another browser, or the matching guide linked below.

A concrete example

Example: you generate 20 characters with symbols, the site rejects symbols, and you generate again with the site's rules. You save the second one. You do not add a 1 on the end of an old password instead. If you must hand it to someone, use a RookSecret burn link.

Where to go next

After you finish Secure Password Generator, open the passphrase page or the breach-check page if the next question is different from the one this page answers. Stay here if you are still on the same job. Extra pages help only when they answer a new question, such as a different algorithm, a different leak channel, or a different file type. The documentation link on this page is the long form of the same workflow, including the checks that do not fit in the tool UI.

If you only remember one thing

Use Secure Password Generator for one job: to generate a random password or passphrase in the browser and keep it out of a server log. Bring the before-and-after evidence with you if you change a setting. A VPN icon, a decoded token, a generated password, or a stripped file is not finished until you have checked the output the way this page describes. Then follow the related guide for the long version, and the sibling tool only when the next job is actually different. Keep secrets out of the same message as the link or the file that needs them. If a second run does not match the first, stop and find what changed instead of publishing the first result.

Field notes

Example: you generate 20 characters with symbols, the site rejects symbols, and you generate again with the site's rules. You save the second one. You do not add a 1 on the end of an old password instead. If you must hand it to someone, use a RookSecret burn link. Work the page in this order: Choose a length you will actually store in a manager. Include the character sets the site allows. Generate. Save the result in a password manager, not in the chat where you generated it. Limits that still apply after a clean result: The page does not remember the password. A password you cannot store will be reused. Generation is not a breach check until you open the HIBP page.

Frequently asked questions

Is this password generator free?

Yes — free at rookvpn.com/pass with no account required.

Are generated passwords stored?

No. Passwords are generated client-side using crypto.getRandomValues. Nothing is sent to any server.

Is the password uploaded?

No. It is generated locally.

How long should it be?

As long as the site allows, at least 16 characters for a random password.

Where do I keep it?

A password manager.

Can I share it?

Through a one-time secret link, not beside your username in email.

Password generator guide Bcrypt hash generator Share a password once