Skip to content
Security

120 random passwords for servers, master keys, admin accounts

120 random passwords generated with the Unbiased Random Selection method (OS CSPRNG with rejection sampling). Lengths from 32 down to 10 characters. Click any password to copy it to clipboard.

ASCII format passwords

The most secure: 86-character printable charset, ~6.43 bit/char entropy. A 30-character ASCII password requires roughly 41 trillion years to brute-force on offline GPU rigs. Use these for critical services: server access, master keys, admin accounts.

Charset: !"#$%&'()*+,-./23456789:;<=>?@ABCDEFGHJKMNPQRSTUVWXYZ[\]^_`abcdefghjkmnpqrstuvwxyz{|}~

32 characters

b2]#N'-dgPF(Z~.[m>/V-3%{u>{v8HW!

^5EYKHg(C-Fp?&$55_YQ`:r~{HXJ*:8f

$n(q[$bYR7(?4WP`BgsB%;QZK$[#a+wn

Fvu`8!amp/-UJn9=V:~H'3pd4h([$K)A

7(3e[9Um|rRw&-[35uVf=$gceqT#yC4S

.ZN8qntuX@,h}+[^=QgY}@>/9zkG$(/(

3~D,bd"E{TxFt-_Y!gZ-"*x+<6)Dr:+R

2e,5`yB85'm<ABut@R;'vPr@`etN@?_m

@E*jSE:W~q9@!PGZR@M765}gwB/2rC8E

9jmn57D"_R)[hE?x}8H+XxD^;5mmFWvA

24 characters

gb&;j}[(F/ph\9X&S|w%q|Xv

."gD,U~G5y/bX~'KUEtB#!"w

*vdjTm8fDd%+:>z':mdV)&Ga

2t'{kjG6[(V;d_f%Fk%3W6S!

xEFzk/+4=Sxr}T7sy{yMTuj&

A-}&Vwvbn.6s*x:={KxQrJ|~

K"-U-7[Jw$ds?@T['zD9;!D+

@/cD{<QNU"(2k}S=QX=fP\><

;#s{#6!Q-BJd*D%~}:DQ<du.

pK.9k{h}VQSQdg3t/:vwMHyq

20 characters

TfJ.@:D7p,VaEM@**zp+

A8BSZMqT[Hk|BMU#8Ba8

_Z8U+v3q2G+TcR_!`St\

S-}KcB$z^mTtBN)sBhd?

4$^&jU!F-UAUDu?M)5NH

caAcE?c?yM;pg:[EST{'

SBqrf)7<(<p@z;/]{(tk

pXb~pZ[N2|,+p[SNg!ZE

5J`(HUqnK&|2)t:<;p7:

N(D={=PN/{8P7^~~$.]D

16 characters

KXC.""canxcdQ95q

4kcM\#=)5=ERbCG\

,\.bX>NT@4K7%v3t

mK8{v}sYbB'bT.vC

(cUuuZXfY[@kuCwN

a?T(|b[w-mJ..Bw`

QP+hTvzj>We'6@P>

>~C~2z\n=ZYB@!~%

5_sb}q/QY]zh$;}R

uB}/;G$5aZ,.-9?'

12 characters

`GY=fy%~F~+e

<2,7E\h|AKQ-

}b9AJu}KPd\}

,[6PpW)}`HYP

/GVD+!%^Pm:6

TdJ!g#U(9ejc

gmGWWefBqBKN

.Jz&f4@F(nwa

"5h7|<ntw!@T

:g[rhz,j>;E7

10 characters

w#**(,f-}U

\k43>ca5y\

(P'Zd_5uM\

g{bgU>@NQw

'[cK5{tJcn

EY4cEMS8PM

tA`?zz4mR*

wY*y2*nM}5

|8&K~g]yD6

+h[=w&8#2F

Alphanumeric format passwords

Reduced charset (54 characters): more readable and typable, lower entropy per symbol. OK for services that forbid special characters. For everything else, prefer ASCII above.

Charset: ABCDEFGHJKMNPQRSTUVWXYZabcdefghjkmnpqrstuvwxyz23456789

32 characters

v5G7z4magDExSXs8RZBwB5MZw83VZeeY

7AapcWmPZqt29RQyeFHx9frqpVTMaVey

9YkDAM5Tpb7gHwwsygVkFTCVqHfhKH6U

jqeu7rfAjatWYjGjYZrXPbVjsbKXJaRS

NJ6GTFZtDzk3YmDeHUrPRXX4fzSEa43G

93jsn3p4JUUwkd4UZxRTmFAmX3pnXWhg

2wuKU3ttQyBM4dUm2FFDAxUvqA7MdkuC

BbRqPPqcTRkdeBhXfDfdTzP3tfeznnnd

n59QhjetJCeKc8VfD79a8geXZSRUJAbD

N5y8CJvXHKVtpDECwg8vGfF2QxSpcZBC

24 characters

FVBRMYVkYtyR7ZqW5f8T4xQc

u4FgjDCbvDqE8AuvYD7dyDEg

F4E3mYaNCp5uj6srwuPJpqDC

8wKVKmvWDATjaJpvzBsMSKfT

jgT3vxZ4fbgECDbAeUGaxSwp

fbsuP2QyyVPQh2J7qXcjfKmc

qGeVwQx3xznYbMkRwa7hXnwg

R2eA5ECUBmpyjuN9CyP4rVEE

TZUNTyZ8PR3Z6bKDPmDUCByW

yUay9rVmNDcTEEmR9yjsyK4M

20 characters

zkCuYtCqvmc49hJubUdy

eDcmnxhsdAFWNQ3UGHqW

SZVZm2jRXzCUeVgpJEw2

JrqgdXF3kBKDTTHWQ5kx

uCSJfCTtqfZG5PpKQe9p

Jp2STJJyjQ8jkEzB7rgc

qfuRXBqmN9GYRFhGA6Xk

dyVgF2KsqnF3FRBPsRbR

SzUvgsDNrREFMCPVd6Wf

pXdyPTcSf8bx9k3J6hqQ

16 characters

KYfcXrusJX4RaEwQ

KjRxpQp3PRsVuTuP

ehyjVte8FVRPwzeG

Svvzu47WgFjbTDUB

pTameZKkk7DwZ5PA

Vkdjk9tHK877BrPV

sbaZQ2Mnv4uvxwTD

NNXTHsAyueXE58uf

eGxUTKUBRbGu7Huh

UMHEBZsXwnfN25GY

12 characters

P6EKcwNwYDGE

CGJ3qdUaHgKH

9MfXMzBabZjZ

2JbXu8mqMWJG

BBsS2vtDGRE3

GEhaJajHGQ2F

XRSDBhYVp4gp

5g8fJnQKcMhv

PQMMPj2tsvYm

5gVnpbqEccpQ

10 characters

THQt74QRHw

WvUXCWj4SV

NTckenyJ5Z

F44DaSACCr

ReS3ZrCFzz

GNrM35ggy6

3gG43TdXs2

7yq6tvPX8r

tHkeCtGBgE

bnuwQJCqjs

Why these passwords are genuinely secure

Generation uses unbiased random sampling via PHP's random_int(), which calls into the OS CSPRNG (/dev/urandom on Linux, equivalents on other OSes), with rejection sampling that avoids the modulo bias many artisan generators get wrong: every character has probability exactly 1/|charset|. On 20 ASCII characters the real entropy is 128 bits. For comparison, a "strong" password picked by a human typically has 30-50 bits of entropy and is brute-forceable in hours on modern GPUs. The passwords served on the page exist only in the HTML sent to your browser: they are not logged, not persisted anywhere, and do not survive page reload.

Frequently asked questions

How long is a truly secure password in 2026?
Personal accounts: at least 16 ASCII characters (roughly 100 bits of entropy). SSH servers, API keys, admin accounts: 24-32 characters. The real security factor is total entropy, not character class: a 30-char ASCII password is more secure than a 12-char password with 'mandatory symbols'.
Why don't the passwords contain '0', '1', 'l', 'I', 'O'?
Visual ambiguity. If you have to read or type the password by hand (on mobile, on a serial console, on a remote terminal), lookalike characters cause errors. Excluding 8 chars out of 94 (0, 1 and the letters I/L/O both upper and lower case) only changes per-char entropy by ~0.13 bits, negligible compared to total length.
Are generated passwords logged or sent anywhere?
No. The PHP that generates passwords runs server-side in an isolated process, doesn't log output, doesn't store anywhere. Every page reload produces 120 fresh passwords that only exist in the HTML served to you. HTTPS always.
Is random_int() really secure?
Yes. In PHP 8.x, random_int() internally uses the OS CSPRNG (/dev/urandom on Linux, equivalents on other OSes): the same entropy source that backs standard cryptographic tooling. The implementation applies rejection sampling to avoid modulo bias, a critical detail many artisan generators get wrong and which leads to non-uniform character distributions across the charset.
Can I use these passwords for encryption or API keys?
For account and service passwords they are fit for purpose. For cryptographic keys (AES, RSA, ECDSA) no: keys must be generated directly with the crypto library that will use them, in the format and length specific to the algorithm. Using an ASCII password as a crypto key introduces an unnecessary KDF derivation, typically done wrong.
What if I work at a company where passwords are shared in an Excel file?
Very common, very risky, very fixable. Migrating to an enterprise password manager (self-hosted Bitwarden, 1Password Business, Vaultwarden) takes 2-3 days of setup + training. If you want a structured path for your SMB, get in touch: this is one of the areas I work on regularly.

Password hygiene at your company is a mess?

If your SMB still uses shared passwords in Excel, reused credentials across services, or lacks a centralized password manager, the compromise risk is high and measurable. I offer targeted consulting on enterprise password policy, migration to self-hosted password managers (Vaultwarden/Bitwarden), and audit of service credentials in use. 20+ years backend + applied cybersecurity.

Talk to me about password security