Generate strong passwords, see real entropy, check for known breaches - without the password ever leaving your device in full

Password

Never saved, never sent anywhere - analysed entirely on this device.

Entropy bars (one per character)

Bars appear here as you type - each bar's height is that character's contribution to entropy, coloured by character type.
lowercase uppercase digit symbol other
-

Estimated crack time

Attack scenarioEstimated time

Breach check

Checks the free Have I Been Pwned "Pwned Passwords" database using k-anonymity: only the first 5 characters of your password's SHA-1 hash are sent, the full hash and password never leave this device. See "How the breach check works" in Settings for details.

Generator

Check history (metadata only - the password itself is never stored)

Default generator settings

These are used to pre-fill the Generator each time the app opens.

How the breach check works

The free Have I Been Pwned "Pwned Passwords" API uses k-anonymity: this app computes the SHA-1 hash of your password locally, then sends only the first 5 characters of that hash (the "prefix") to the API. The API returns every hash suffix in its database that shares that prefix - typically several hundred - and this app checks locally whether your password's own suffix is among them. Your real password, and even your password's full hash, never leaves this device. This is the same technique used by browser built-in breach warnings.

Data & privacy

This app never writes a typed or generated password to disk, in this app or anywhere else, and never transmits one anywhere - the only network call it makes is the opt-in breach check above, which sends a 5-character hash prefix only. This is a strength and generation tool, not a password manager - it does not store or sync your passwords for later retrieval.