jkssh

Password Generator 15 Characters

Many websites and company policies ask for a password of at least 15 characters. This generator creates truly random 15-character passwords with your browser’s cryptographically secure random number generator — nothing is sent anywhere. Choose which character types to include, leave out look-alike characters, make several at once and see how strong each one is in bits of entropy.

15-character password generator

Password Security Kit

Printable account security kit: a home account security checklist, a password-manager setup guide, an MFA setup tracker and a family online safety sheet (no password storage sheets — use a password manager).

Formats: PDF, DOCX, XLSX. Instant download after payment (link valid 72 hours, up to 5 downloads). AI-assisted: the templates were drafted with AI help and reviewed and laid out by Kedop.

$3.00 USD, one-time

Secure card checkout by Stripe. Full refund within 7 days — see the refund policy and license.

Why 15 characters?

Length is the single biggest factor in password strength. Guidance has moved away from complicated composition rules towards longer passwords: the US National Institute of Standards and Technology’s digital identity guidelines (SP 800-63B) set a minimum of 8 characters for user-chosen passwords and recommend allowing much longer ones, and many organisations now require 12 to 15 characters or more for staff and administrator accounts. A random 15-character password using letters, numbers and symbols has around 95 bits of entropy — far beyond what can be guessed by brute force.

How strength is measured

Character setPool sizeBits per character15 characters
Digits only103.350 bits
Lowercase letters264.771 bits
Upper + lowercase525.786 bits
Letters + digits625.9589 bits
Letters + digits + 13 symbols756.293 bits
All 94 printable ASCII946.5598 bits

Entropy = length × log₂(pool size), and it applies only to passwords chosen truly at random — as this generator does. Human-chosen passwords of the same length are far weaker because people follow patterns.

How the generator works

  1. It builds a pool from the character types you tick, removing look-alikes if you ask.
  2. For each position it picks a character using crypto.getRandomValues, the browser’s cryptographically secure random number generator.
  3. It uses rejection sampling so every character in the pool is exactly equally likely.
  4. If you require each type, it discards any password that misses one and tries again.
  5. Nothing is stored or sent — close the page and the passwords are gone.

Worked example

With uppercase, lowercase, digits and the default 13 symbols, the pool is 75 characters. A 15-character password then has 15 × log₂ 75 ≈ 93.4 bits of entropy, about 10²⁸ possible passwords. Even an attacker making a trillion guesses per second against a stolen password hash would need, on average, hundreds of millions of years. Excluding look-alike characters shrinks the pool to 69 and the entropy to about 91.6 bits — still very strong.

Storing long passwords

When sites reject symbols

Some sites limit which symbols you can use or cap the length. If a password is rejected, edit the symbol set to include only the characters the site allows, or untick symbols and increase the length by a few characters to keep the same strength — 17 letters and digits give about the same entropy as 15 characters with symbols.

What makes a password weak

When to change passwords

Current guidance advises against forcing regular password changes, which tends to produce predictable variations. Instead, change a password when there is a reason: a breach notification, a suspicious sign-in, a shared device or a password you know was reused elsewhere. Generate a completely new one rather than tweaking the old one.

How attackers guess passwords

Most password cracking happens offline, after a website’s password database has been stolen. Attackers try lists of leaked passwords first, then dictionary words with common changes, then brute force. Well-run sites store passwords with slow hashing algorithms that limit how many guesses per second are possible, but you cannot know how a site stores yours. A long random password defeats every one of these methods, because it is not in any list and the brute-force space is enormous.

Passphrases vs random passwords

A passphrase of five or six random words (for example, chosen with dice from a word list) can be as strong as a 15-character random password and easier to type on a phone. Random character passwords are shorter for the same strength, making them ideal when a password manager fills them in for you. Either way, the key is that the choice is random, not a phrase you invented.

Privacy and security

Passwords are generated on your device and never leave it. Kedop does not log, store or transmit them. For extra caution, you can load the page, disconnect from the internet and generate passwords offline.

Frequently asked questions

Is a 15-character password strong?

Yes — a random 15-character password with mixed characters has about 90–98 bits of entropy.

Are these passwords truly random?

They use your browser’s cryptographically secure random number generator with unbiased selection.

Are generated passwords saved or sent anywhere?

No, they exist only on your screen.

What are look-alike characters?

Characters easily confused when read, such as I, l, 1, O, 0 and o.

Can I make longer passwords?

Yes, any length from 4 to 128.

Should I use a password manager?

Yes — it lets you use a unique strong password for every account.

How many passwords can I generate at once?

Up to 20 at a time.