Ask ten sign-up forms how long a password should be, and most of the ones that bother to answer will say 12. It's a sensible baseline rather than a law of nature. The one official benchmark worth knowing is NIST's SP 800-63B-4, finalized in 2025: a service should require at least 15 characters when the password is the only thing protecting an account, and 8 when a second factor is also required. Twelve satisfies most sites. Fifteen satisfies the strictest standard around.
Three extra characters sound minor, but every added character multiplies the search space rather than adding to it. With all four character types switched on, this generator draws from 80 symbols per position, so a 15-character password has roughly 500,000 times as many possible combinations as a 12-character one built the same way. That gap is the difference between a password a well-funded attacker might eventually grind through offline and one they will not bother attempting.
Where the number 12 actually comes from
Twelve isn't arbitrary, but it isn't cutting-edge either. It's roughly where password-strength guidance settled a decade ago, back when the main worry was a human trying a handful of guesses at a login screen, which most sites now also slow down or lock out after a few failed attempts. The bigger risk today is different: a company gets breached, its password database leaks, and an attacker runs cracking software against the stolen hashes on hardware built for exactly that job, unconstrained by any login limit. Twelve characters still holds up against that, provided the password is fully random. It just doesn't hold up as comfortably as it did when the guidance was written.
When 12 is fine
Use 12 when the site caps length, when two-factor authentication is already switched on for that account, or when you're creating a low-stakes login you wouldn't lose much sleep over. The number is a floor rather than a target, and in practice you'll rarely type it by hand anyway, since a password manager pastes it in for you. A gaming forum, a newsletter sign-up, a one-off account for a service you'll use twice, none of these need the extra four characters that fifteen brings.
When to go to 15
Pick 15 for anything that stands on its own: an old email account with no authenticator app attached, a router or NAS admin login, a server or admin panel, a shared drive that several people can reach. Because you're pasting rather than typing, the extra length costs you nothing at the keyboard. If you find yourself needing to type the secret by hand instead, a passphrase of random words is a far more forgiving way to hit the same strength than fifteen random symbols typed from memory.
Your email deserves the longer setting more than almost anything else you own, since it's the recovery route for most other accounts you have. If someone resets your email password, they can usually reset everything downstream from it too. The email password guide goes into that specifically.
If a site rejects symbols
Some older sign-up forms still refuse punctuation, or only allow a narrow set of it. When that happens, switch the symbol option off here and lengthen the password instead of shortening it to fit. Fifteen characters of letters and numbers alone still carries far more combinations than twelve characters that include symbols, because length multiplies the search space more aggressively than adding one more character type does. This is also the reasoning behind what makes a password strong in general: length first, character variety second.
A quick way to picture the difference
It helps to think in terms of guessing speed rather than abstract combinations. Say an attacker running cracking hardware offline can test a hundred billion guesses a second, which is realistic for stolen password hashes and specialized equipment. A fully random 12-character password from this generator would take that attacker somewhere on the order of decades to work through exhaustively. The same setup at 15 characters pushes that figure past anything meaningful to plan around, well beyond any attacker's patience or budget. Neither number is small in absolute terms. The difference only shows up when you consider that attackers don't need to crack one password; they need to crack as many as possible across a stolen database, and shorter passwords are always the first ones to fall.
Presets, or your own length
The two preset buttons on this page jump straight to 12 or 15 with sensible defaults for the four character types. The slider underneath covers the full range from 8 to 64, so if a site asks for something unusual, say a 20-character limit for an API credential, you can set that exactly rather than settling for the nearest preset. Longer than 15 is rarely necessary for a login a human owns, but it's the right call for machine credentials: the random string generator is built specifically for that case, with options this page doesn't need, like hex-only or alphanumeric-only output.
One length doesn't have to fit everything
It's tempting to just pick fifteen and use it everywhere, and that's not a bad habit if you'd rather not think about it account by account. But different accounts really do carry different stakes. A social media account tied to your real identity and your contacts' trust deserves the longer setting. A router login you'll change again in a year is a reasonable place to stick with twelve. If you'd rather have one tool that adjusts to whatever you're protecting, including a strength checker for passwords you already have and a passphrase or PIN option alongside the password generator, the full password generator keeps all of that on a single page. There's also a WiFi password generator if what you're actually setting up is a router or guest network rather than an account login, with a matching QR code tool for handing it to guests without reading it aloud, and a separate PIN generator for keypads and lock screens that only take digits.
What happens when you press generate
Whichever length you land on, the password is built the same way: characters are picked one at a time using your browser's Web Crypto API, the same secure random source used for real cryptographic work, with an unbiased method so every allowed character has an equal chance regardless of length or character set. Nothing about the process leaves your browser tab, and nothing is stored once you navigate away. You can confirm that yourself by opening your browser's developer tools, watching the Network tab, and pressing generate a few times; no request goes out. Pick your length, copy the result into a password manager, and that account is done.