Skip to content
Security

120 random passwords for servers, master keys, admin accounts

120 random passwords generated with the Unbiased Random Selection method (OS CSPRNG with rejection sampling). Lengths from 32 down to 10 characters. Click any password to copy it to clipboard.

ASCII format passwords

The most secure: 86-character printable charset, ~6.43 bit/char entropy. A 30-character ASCII password requires roughly 41 trillion years to brute-force on offline GPU rigs. Use these for critical services: server access, master keys, admin accounts.

Charset: !"#$%&'()*+,-./23456789:;<=>?@ABCDEFGHJKMNPQRSTUVWXYZ[\]^_`abcdefghjkmnpqrstuvwxyz{|}~

32 characters

)!Wy#UR8q<;ZFH:KQ)SVwSUCybY"{;a3

g~DV]CC^-AGY4'=|*HR~R|$Kn+m]V/98

@f<Mxsec;|(8MS_sP{-{XZF2|hTf6j}/

ZU$Sursc9/W\PcEtWC]&9rD3x[Z&VB%x

b$%;=Y$Zp(`dcs#2bBtb#|`z]\V/bu*H

ND4_^9Pb(2c;h:5B6tn6SQ@e*=;F8cW@

h')N,Sw[EK-Sa~4c@!^x(UMXCYM_(J%c

`)Us;&+&tj87-[[5w|GzXM.@Ca&ME]|P

E<V=[`WA(Sh#rC/br?"EQY=6e-Pp?]wv

!<bAH_a]f%bVh88X>jS^Fumh/4c{!E>4

24 characters

`P`%{}&9;e$sQ'MWK+g:PF6w

Zd,q=zay#$`ra=,yQ^G4]z^a

%Jm[e!nU^B_x7Q&am8=!T#5*

wRVFM[Ee}y_HT'X><}%/m)x=

v=$6gmCFP\HW[F5>Zrb-sTnk

~FTm6XT.`KQyH?]fEZ[FK=V^

`3n.T,ntw7FVDtN(vJ]z`fnj

H*xZGG5f+'=8#UH}$~nd9eT{

<n#|SH?We&+'$V6vmP^S_YjJ

'd9"!9ktF|Fn"E"\":DT,4}B

20 characters

8mfud@<7zZTZC*(x9~`/

/m##C5:Scbm6@H>BuZ{j

Jp`gdEhs+Q;HXPX9QR\z

4jT${}ZX=x\_9f;Xst)7

5]<j]E=ngs,#e7[F-CH*

;G"*U\*yvUhG&J9bNdq\

.{[>{%tv-gwmd{!kdehp

2EW+ep%]*h6rF&_Eu&:x

9+hC"(QE-P|=5t,ErD[c

U/jjRg@xVt%;hqU7z(tD

16 characters

(SyJ}uAmH*6<~?A|

f:U2V`ZH&%TJ-3X=

Z.m4mM~|"yzm~28h

Q>7!n$$8Vx(S3W8u

]E3G!NM?J&Sp}U'H

paM\}ub&ZxmTJrez

;{$HX3/gPJ7$B8H$

W%J(gXcr@5?/[';3

.XA6U^q4h{Hg8S+\

RNWbDa(qk+YJcBtA

12 characters

.|<az<r-4A,=

>Z.NH6{F.9jJ

,7WWrZZP&$]4

vC*;HDT[XXn(

%sd{X_Wtf9%G

_G_V!H4g)Ty^

?xp+gqx#Fj-K

htTwc\Q[v|Mv

!UTMxJ"Ufv{,

FF<*R^/Z4-c6

10 characters

f)A;5BCrW%

X5px9RGd$&

rkaa>yMg(G

r}8>G.(*{m

v\GTTq;}TB

+AKX5Gv2XG

D6z}~w?Vhv

sN[.uScyx%

P@}4J.uNVk

GDs"p\Sq7J

Alphanumeric format passwords

Reduced charset (54 characters): more readable and typable, lower entropy per symbol. OK for services that forbid special characters. For everything else, prefer ASCII above.

Charset: ABCDEFGHJKMNPQRSTUVWXYZabcdefghjkmnpqrstuvwxyz23456789

32 characters

tdmBfK7WNyAeQ53tQ9YXSDAPZXy2vbZZ

acb9x25sq5FbjqqxbXXssrrWx32YWbY5

G347BY9sJUg6S37FxzH5ncgWQ25nxYNw

fDZYQQEJXraDTRA3DHZEUWyhphEv5Sje

udFFVQWVVNcK2ZVVUwtZsXu97CS2kK9J

UFZVS9qd63QCkqdRe4uE7GvnQqQSnyjJ

CgkGx6ScQDfYTaQ5buzJd68NeqdbmtST

AkNXDYsxAMDjYdJ8SFNANz4EfK3pNeW3

GSEuZzMZV5qU3nFgdhG4NYqdm4UbmWYH

suYHfWtQFerraSxfK9Va8GbmUUUtgZba

24 characters

JEqYGzWNT83tducjeDYTvs98

TTuE2PuXsTehvKRzjAARXZ47

7Y7dPUrMgV24QMfYC4Y3vWzv

uH5xhNSAcRyWXdaAQfNxrbgC

hpkjwRYEJUFccrCucKCpYU2m

hPxyAjKJCfVp9REC6dBWBR5D

zZ6Qm4kDNnQtPKBuKZXQ3n32

PB4QW7h85RjEs7ckwWJUE74M

Pu6YbHS57gbwd8JHVsjuuptT

CDcaP9qJqcWBg9EzhRtR3hqN

20 characters

KPkBtKGGWpHmJPnDq3Kd

xZpr5pCJqMtuREnTFt6S

C4mf6WRjRpUwJWQpykDw

9DMxrXwebtceR8cd28rK

CWSwBQ8GKgKcYNxpSEAT

aS59NW3qduPPTdrV6wFN

364qstYRG2gG2mMXfnDb

ub7hahGFezwbY4mdQmxV

BfD5RfUAQHxjEXh2HAaG

e3kPyJCjmxWyrbCsW5TB

16 characters

m3Auq3JWECfyCJcg

AKhUH8F5CST59f57

ARmkDVkNh2d2Frpn

qFNUNnn8tu6GkX6J

vG7GzWJZcj5xS8px

Tq7NwcxKMkTE877z

dnvFvJnS3J23drQH

zVTCxykkjbnHA9DT

dwYPcsn9Kud3478r

fSpw7y9UQFvZ82yS

12 characters

ugPBrAGJSTfZ

WBCaFyDTM7QN

haCpdBwKn9tr

ewtb9SZQyzWN

Q44KgeksX7Qz

YX9N2a4KfRRb

9XP8UeN7U5jJ

Yg6X2v2YNGqd

yPRSFcxejzVE

mWjc8CffUsW6

10 characters

nsYThsVKqB

CwMhggEuhR

kdA7UswD2H

XPcSeAc5Vg

dvaykuW3zz

KFfyecCASu

Z3Jsuc9KJT

eHd6syAD4C

jCPNeGsHsZ

n3k8SCWeRc

Why these passwords are genuinely secure

Generation uses unbiased random sampling via PHP's random_int(), which calls into the OS CSPRNG (/dev/urandom on Linux, equivalents on other OSes), with rejection sampling that avoids the modulo bias many artisan generators get wrong: every character has probability exactly 1/|charset|. On 20 ASCII characters the real entropy is 128 bits. For comparison, a "strong" password picked by a human typically has 30-50 bits of entropy and is brute-forceable in hours on modern GPUs. The passwords served on the page exist only in the HTML sent to your browser: they are not logged, not persisted anywhere, and do not survive page reload.

Frequently asked questions

How long is a truly secure password in 2026?
Personal accounts: at least 16 ASCII characters (roughly 100 bits of entropy). SSH servers, API keys, admin accounts: 24-32 characters. The real security factor is total entropy, not character class: a 30-char ASCII password is more secure than a 12-char password with 'mandatory symbols'.
Why don't the passwords contain '0', '1', 'l', 'I', 'O'?
Visual ambiguity. If you have to read or type the password by hand (on mobile, on a serial console, on a remote terminal), lookalike characters cause errors. Excluding 8 chars out of 94 (0, 1 and the letters I/L/O both upper and lower case) only changes per-char entropy by ~0.13 bits, negligible compared to total length.
Are generated passwords logged or sent anywhere?
No. The PHP that generates passwords runs server-side in an isolated process, doesn't log output, doesn't store anywhere. Every page reload produces 120 fresh passwords that only exist in the HTML served to you. HTTPS always.
Is random_int() really secure?
Yes. In PHP 8.x, random_int() internally uses the OS CSPRNG (/dev/urandom on Linux, equivalents on other OSes): the same entropy source that backs standard cryptographic tooling. The implementation applies rejection sampling to avoid modulo bias, a critical detail many artisan generators get wrong and which leads to non-uniform character distributions across the charset.
Can I use these passwords for encryption or API keys?
For account and service passwords they are fit for purpose. For cryptographic keys (AES, RSA, ECDSA) no: keys must be generated directly with the crypto library that will use them, in the format and length specific to the algorithm. Using an ASCII password as a crypto key introduces an unnecessary KDF derivation, typically done wrong.
What if I work at a company where passwords are shared in an Excel file?
Very common, very risky, very fixable. Migrating to an enterprise password manager (self-hosted Bitwarden, 1Password Business, Vaultwarden) takes 2-3 days of setup + training. If you want a structured path for your SMB, get in touch: this is one of the areas I work on regularly.

Password hygiene at your company is a mess?

If your SMB still uses shared passwords in Excel, reused credentials across services, or lacks a centralized password manager, the compromise risk is high and measurable. I offer targeted consulting on enterprise password policy, migration to self-hosted password managers (Vaultwarden/Bitwarden), and audit of service credentials in use. 20+ years backend + applied cybersecurity.

Talk to me about password security