Toolkit
Password & secret lab
Estimate how long a password resists an offline attack, and generate cryptographically secure secrets and passphrases. All computation happens in your browser.
Strength checker
Runs locally — nothing is sent anywhereSecret generator
192 bits of entropyUses the browser’s cryptographic RNG (crypto.getRandomValues). Ideal for JWT secrets, API keys and session keys.
Passphrase generator
~40 bitsMemorable and strong — good for disk encryption or a password manager’s master password.
How the estimate works
Entropy is estimated from the character set and length, then reduced for patterns an attacker tries first: dictionary words, keyboard runs, repeats and years.
Crack times assume an attacker already has the password hash and runs a single modern GPU rig. A slow hash like bcrypt buys enormous time; a fast one like MD5 buys almost none.
Figures are order-of-magnitude guidance, not a guarantee. When in doubt, add length.