PIN generator

Generating on your device…

Calculating

 

PIN options

For phones, bank cards and other places that lock after wrong guesses.

When a PIN is enough

Six digits are only a million options, so use a PIN only where wrong guesses lock you out, like a phone or bank card.

Skip birthdays, repeats and patterns like 123456: they're tried first.

How your passwords stay yours

No server ever sees them. You can check every part.

Made on your device

Every character comes from crypto.getRandomValues, the browser's cryptographic random generator.

Numbers that would make some characters likelier are thrown away, so every password is equally likely. Without secure randomness, nothing is generated.

The function every character passes through
export function randomInt(n: number): number {
  if (!Number.isSafeInteger(n) || n < 1 || n > UINT32_RANGE) {
    throw new RangeError(`randomInt needs an integer range between 1 and 2^32, got ${n}`);
  }
  const source = secureSource();
  // 2^32 is rarely a multiple of n, so reducing every draw modulo n would make the low results
  // slightly more likely. Draws at or above the largest multiple of n are discarded and redrawn;
  // even in the worst case under half of all draws are rejected, so the loop ends quickly.
  const limit = Math.floor(UINT32_RANGE / n) * n;
  const draw = new Uint32Array(1);
  for (;;) {
    source.getRandomValues(draw);
    const value = draw[0] ?? limit;
    if (value < limit) return value % n;
  }
}

Nothing is sent

Generating and checking make no network requests, and the security policy would block one. The counter tracks every request to another site.

Check it yourself

  1. Open developer tools (F12, or Cmd Option I on a Mac).
  2. Choose the Network tab.
  3. Generate and check passwords. The list stays empty.

Or turn on airplane mode: after one visit, it still works.

0

requests to other sites since you opened this page

Works offline after your first visit.

Locked down by your browser

A strict Content Security Policy stops the page loading outside scripts, sending data elsewhere, or being framed, even if its own code had a bug.

Here is the exact policy this page arrived with.

default-src 'none'
Block everything that is not explicitly allowed below.
script-src 'self' 'sha256-wzSTKVRzhp6995mnNaSiDXEUvxIxwPJxho/of/nQob0='
Only SecurePass's own scripts, plus one inline theme script pinned by its hash.
style-src 'self'
Load styles only from SecurePass. No inline styles.
img-src 'self'
Load images only from SecurePass.
font-src 'self'
Load fonts only from SecurePass. No font CDNs that could log your visit.
connect-src 'self' https://api.pwnedpasswords.com
Requests go only to SecurePass, and to the breach check when you ask.
manifest-src 'self'
Read the install manifest only from SecurePass.
worker-src 'self'
Run only SecurePass's own offline service worker.
base-uri 'none'
Stop injected markup from redirecting where relative links point.
form-action 'none'
Nothing on the page can submit a form anywhere.
frame-ancestors 'none'
No other site can embed SecurePass in a frame to trick you.
object-src 'none'
No plugins or embedded objects.
upgrade-insecure-requests
Any plain HTTP request is upgraded to HTTPS.
require-trusted-types-for 'script'
The page cannot turn text into code. Every script URL has to pass a reviewed policy.
trusted-types securepass
That policy exists for one job: registering the offline service worker at /sw.js.
The other security headers
Strict-Transport-Security
Browsers must use HTTPS for securepass.dev for the next two years.
Referrer-Policy
Never tell another site which page you came from.
X-Content-Type-Options
Browsers must not guess file types, so a file can't be passed off as a script.
X-Frame-Options
The older form of the frame ban, for browsers that predate frame-ancestors.
Cross-Origin-Opener-Policy
Other windows cannot keep a handle on this page.
Cross-Origin-Embedder-Policy
The page refuses resources from other sites unless they explicitly opt in.
Cross-Origin-Resource-Policy
Other sites cannot load SecurePass's files into their pages.
Permissions-Policy
Camera, microphone, location and 29 more are off. Only clipboard writing is allowed.

Nothing stored, nothing tracked

No accounts, cookies, analytics, ads or third-party scripts.

Only your settings are remembered, in this browser. Clearing site data removes them.

Remembered on this device

  • Length and character choices
  • Passphrase and PIN settings
  • Light or dark theme

Never kept anywhere

  • Generated passwords
  • Passwords you check
  • Breach check results
  • Your IP address, device or visits

A breach check that never sees your password

Have I Been Pwned holds hundreds of millions of leaked passwords. k-anonymity looks yours up without sending it, and only when you ask.

  1. Your device hashes the password with SHA-1.

    password 5BAA61E4C9B93F3F0682250B6CF8331B7EE68FD8

  2. Only the first 5 of 40 characters are sent.

    api.pwnedpasswords.com/range/5BAA6

  3. Every leaked hash starting with those 5 comes back, padded with decoys.

    0018A45C4D1DEF81644B54AB7F969B88D65:count00D4F6E8FA6EECAD2A3AA415EEC418D38EC:count…1E4C9B93F3F0682250B6CF8331B7EE68FD8:count…

  4. Your device looks for the other 35. The service never learns which, if any, was yours.

    1E4C9B93F3F0682250B6CF8331B7EE68FD8 found

Data: Have I Been Pwned. No cookies or referrer are sent, and it is the only other site the policy allows.

How crack time is estimated

The headline assumes a well-equipped attacker, so it never flatters.

Generated: exact maths

Strength is the number of passwords your settings could produce, in bits: about 131 for 20 characters, 77.5 for six words. Time is half of those guesses at the attacker's speed.

Typed: pattern analysis

zxcvbn finds the words, names, dates, keyboard runs and substitutions cracking tools try first, and counts the guesses they take.

Attack speeds used for the estimates
AttackGuesses per secondAssumption
Online, rate-limited100 guesses per hourGuessing through a login page that slows down or locks out repeated attempts. This is zxcvbn's throttled-online assumption. Source
Online, no rate limit1,000 guesses per secondGuessing against a login or API that never slows the attacker down, which OWASP warns against. The service itself becomes the bottleneck. Source
Offline, slow hash100,000 guesses per secondA stolen database protected by a slow password hash (bcrypt, cost 10), attacked with twelve RTX 5090 graphics cards, as in Hive Systems' 2025 password table. Source
Offline, fast hash3 trillion guesses per secondA stolen database protected only by a fast hash such as MD5 or SHA-1, attacked with twelve RTX 5090 cards at about 220 billion MD5 guesses per second each (2.64 trillion in total), rounded up. Source

Ratings

  • Very weakunder 45 bits
  • Weak45 to 59 bits
  • Fair60 to 74 bits
  • Strong75 to 99 bits
  • Excellent100 bits or more

Good password habits

From NIST SP 800-63B-4 (2025).

  • Length beats complexity

    15 characters or more. Length and randomness count, not symbol rules.

  • One per account

    Reuse turns one breach into many. A password manager makes it easy.

  • Check for breaches

    Leaked passwords are the first ones attackers try.

  • Change when there's a reason

    Not on a schedule: when there's any sign of exposure.

  • Add a second factor

    Passkeys or two-factor sign-in make a stolen password useless on its own.

Questions

Does SecurePass send or store my passwords?
No. Everything runs in your browser and nothing is sent, saved or logged. The only outside request is the optional breach check, which sends five characters of a hash.
How can I check that for myself?
Open developer tools, choose the Network tab, and use the tools: no requests appear. Or go offline after one visit; it keeps working. The network counter shows the same live.
Does it work offline?
Yes, after your first visit. Only the breach check needs a connection.
Is the breach check private?
Yes. Only the first five characters of the password's SHA-1 hash are sent, and your device finds the match itself. How it works.
What can't SecurePass protect against?
Anything already on your device or watching your screen: malicious extensions, malware, clipboard history or sync, or someone looking over your shoulder. That's why you can hide the password.
Why does the checker rate a long password as weak?
Length only helps when it's unpredictable. Common words, names, dates, keyboard runs like qwerty and swaps like @ for a are tried first, so a long password made of them can fall in seconds.
Should I use a password or a passphrase?
Both are strong when random. Passwords suit a password manager; six or more random words are easier to type and remember, like your password manager's own password.
How random is it?
Every character comes from crypto.getRandomValues, the browser's cryptographic random generator, with no bias: every password is equally likely.
Is it really free?
Yes. No ads, accounts or tracking, and the source code is MIT licensed.