64-Character Password Generator

A password generator set to 64 characters. Generate secure, random 64-character passwords — 413 bits of entropy with the default symbol set, maximum strength. Everything runs in your browser.

Use + D to bookmark this tool
pwgen — 64 chars
guest@pwgen:~$ generate password --length=64 --all-chars
<gA6cad2uDS>9G;PZqUObD3#[J|<[whw0..D.8UmOKwb;G*F-rEWnGJAagLlN0FN
excellent · ~413 bits
length
64
charset
options
symbols
[init] crypto.getRandomValues() — ready
[info] all generation client-side · your password is never sent anywhere

Using a Password Generator for 64 Characters

A 64-character password provides 420 bits of entropy. At this length, you're generating a cryptographic key rather than a traditional password. The number of possible combinations exceeds the number of atoms in the observable universe by a factor of 10⁴⁶. This is used exclusively for machine-to-machine secrets where maximum theoretical security is required.

Entropy is calculated as: length × log₂(pool_size). With 64 characters from the full 95-char printable ASCII set, you get 420 bits of entropy. Brute-force time at 10 billion guesses/sec: 1.2 × 10¹⁰⁹ years.

Example 64-Character Passwords

<gA6cad2uDS>9G;PZqUObD3#[J|<[whw0..D.8UmOKwb;G*F-rEWnGJAagLlN0FN
o]T<;a0AIm$r2It|OV)Aw?ZE#k#!eK)n.6kddra]b^-O)Z2;5X74Cs+7LTuD-uWe
4{doMqpn[,oy3EBHj]8R;n<DZb&e9owKIVf46ChWT8_^O+!LbB-PV]r!s]yuefw]
j?ROS=+}|Gi_S<VJfQdL15^<#67y?teS(>A^J9H6=mSv5*+$F++&jrN}1Ks6C!fV
vrX*tg@=FGi^K=A<%lZ7ggLk.fB.S>_FZICC0W$FS+]EZCv^mIl7P(iX-)HOf@*X
jX(aod5(G{9y@jX;fa0y{IWD0]jC:dd01cXR^<<]M2zR6sK$x&ph,@=TCJaTT}RS
iAk|xuYDfP#$GD9]j?D8dF01V_?G|M$zT>9Al_Z-3KSB|CGUsOkSVf^Hnq4-LfE,
PXp>uRd+U.h.#q-kZ,UosUQu5[):2kPEeTi_KrcP{6IP*Di8xB}_J<^F?9=Z<[[)
L{tl*_x1l3[pI::EFN]pCA}G8([;07sB(Z8NIml_k{V-{CCO9cv.D](n3v{vx8x0
r>,7dVKx3}>N$^4ZD5.*kFH<]766a]YH|E-Ch4qj{sw{aigJkO|WV,*&wmyFmJT|
^<I+aFSq$0wpdwC.2Ox@W:Q{>O}K|bI+|!@d@JY=S5eA?OT[=cTYf*ikVqE?#D@6
YF.qW|5[|hJ9q}.#L@RAT<qyATg(G.vGi@$I0i=riMq.sX_dIYcy8c+BW9K:pNlV
X@x)|zcc|[sd<h><r8g*5|%_Sde%i*V8]_$]}^gVG__i7yo0Dqv!A:rNOm%=YR,%
RHWt2M@*B*C#HutN=b4jC^W^gRC_gnkz[G<XF&0h3M!=zPLu9>!%(F?<<Fj8|reQ
nO3#-GfI6IbmC+BN?T9diF?4=yhFLK>n{e1SAv7:%.g:vA?ix%w%j(LagE)W!$xl
Kng_DmQ^+sliPPie@f8)5;f^8vs0[EKZJ!+MMn%X6mr0<l4u,x41oH-[h7pfgA.0
nY%^qm3G;ZvwFOuU}F7OF?wj0I2i(wbWOrapL^bL3vug>>w=*nG4IZU%*m-zb5x:
_]h(=R-ljB>R*T#|*Z+ckU(:<[>{XG8(l3=8;rbq>T{mv0TxEa5}KFGq1R1hF8I@
ODD8-raVBHvW)%u|<]0}^Tn(Z:>BKcKtEbv*pqM03wx6B#i+(ULpx_?TXl0o&y}4
ySiYZ*z-55*h%w0nu!UT>B*oTd0jIh;iTA#EMz|>eagf_7}A&TjVhJS8TIQH!neH
S+:(mVKSUA?SA[eC[f!tr#SM94jp|x:UC?fx(IDmQ:vp.cXKy-O?m.F$S(&Kr-J5
,;ibF-*2P<D2:g!pN;qg(_iDHlw4E<V+txn(fo21PS&&.nn(cFE-aD&=YCgtrs8,
T{*<pP)cy%<EMFngOP}Pol?.,xSF95Rw?+wE<qOi:pqd%GR:VBxJ#xt.2uE,0NY5
=gQdSjA!2tt8)$UQHO|b_v}2A^p)Q>P[I}6P{lf}FMs@xyUy;{(ouw_:>lN&GuoE
Wr:=V1B@xv%;}OlMt?JrUf4+j|,TclRa^)_[6G*)AuIjn37*Tns+EPpqQh*T@fy0
GS9;?]p5-waBQ?-l)Mene;L2Nl:rbg{%s,qWeAEsk09*Yz+&!)zHQHn=T#P=Zs.[
fb5#NqGIiRP;$7Ls0?eE_Rbqvctizl_7d-VR=Y<iMj[{?Xhp?ug2i>1HC%3n#8mm
dVBJd3TV0_RSuATv]-jzy$qJ(_Pn3J762G,[Y;!fljt60QF?-4;_Pa]zl,I%B<^s
iP4ua}#j5n>0}T65mdNveiS|$UB+B$Pb-wp{:I}{Anuamx)M_)QnBBYiuP5OMLMJ
|Wv0gl6s#QS]M=nrQD}KpdGuzf)}T1@FD02q>gK>Sck?r8h-qO;COtvf3teeLL8p
6akf:.]++|rv}V:S-Y8vl2ePzGHp;F}k@<!*km1VIGsemA^<.PC44$x)nspbjCf_
(?qm:*5S]=:9-v]Sk-rqN;UdI;?n>{!HUZbteII)&|P[#:W]Z2gpn9kW+=V(C7<Z
d|2ZnOE$wIcFF^k48y!b;96H^5NS-F1ic)CbmDl4Sw6E4g|p5^DMN-mT2M}z(H.#
NHXr|T%5%]tRlR6]<@D@;8%3yGrh@^W-:gd)KNFEBn1v?:obfdBu|Xj1Iui&(!hb
MWw*cGZPhmTXp!#XVq?6#SEtBe.1<s^_4!v{S=ml2$B6E2joK%@fZao%r&%*b{gQ
0(4Nk=bQ_{e9WwP*mG(QdoLBf=fLZ!<bj!I(R6>_G<w5ueOJ$4EEHVf{x<:==FfD
5l2fd9TBS$f_bq>4+2B-*PE==5)}}$AV=%mj&hcsJ3:WloVSgi0,JtWmqDay4wv=
w6&E|+q+exm0]y^z_xr.])Dv4GRkx1!Y!Jv5-[6idR<Gk#a2NN19[{HZ-<lHkIQM
A*m(Q,]{u;m3*P:*}5UY}&ZZ7kLNFKhgBns25y{-FWaq0pXgcEI4dmqSe^XGoQvx
xF(];oQ)HjQbdJgn-E8<hoh)]-j2lVnvU%^qTuMo};$V44D|3t2FGgC<X,.x5{6H
#u[VnunA.^o@-sv1zZ#o#AinT!a{Bj0Id]mAALrLLInNZu%aD}ZiorHg{)VtK$X5
p#eZ-5h=!djcH(4&x%0sR4g.BoRx#Ri+K7ZU|K&iRsXjoWXtF?HWv@@fuelGU;wZ
VC<k}#Xz}_894lOo%6:8ZjmDq^dY6$}SCa4)E3HuZ(_[:G&Y=:3Rx#rsQpR=JjCa
J:j,J.>&OeTZ{-uR7n7^LWUs2wR,!q+o$lUb.d^KrFX*|CYC*L9XHu3+kirrzXgM
P;!Q0YPYI?(D*O*_TE8bAULrLfXFuw^RK;,9AV}7dH{(,:s[!}+!aY1#PKITf}F!
KV@A_$i]rNE(kqUCU_Q4FXX0c(nPzNxv1b,v2xto#0c$o5c:eRw@5YMpWQ8p1..U
tor3IK5?<39i5>430e0dv0OY>tTG;_E5WapK)39wUMDN>mnN2yEp8%^{?qgKNLq{
xM(r,fm$a0K[fJ+9gczNL8;8@%pSGo.%A7##4r)kGiV{n5lSftpwN+2:754gFD5S
I:QI[ay70M#W:gAS}{,xQ%+OCEJ=Z4RasNE:Mn?Jt]vI8m|nvvBOU0&Z!iZ@z:S:
2+r@h;sQW2aLgj^EkGLYH||P[>|X.ipu.ovu34mCx+t%nK@&u0V:BJcFw4O3@nF(

50 pre-generated examples. Use the generator above for a cryptographically fresh password — these are for illustration only.

Who Needs 64-Character Passwords?

HMAC-SHA512 requires a 64-byte key for full security. Ed25519 private keys are 64 bytes. Some enterprise token systems (Vault, CyberArk) generate 64-character secrets by default. AWS Lambda function URLs use 64-character authentication tokens.

64-Character Password Use Cases

HMAC-SHA512 Signing Keys

JWT HS512 secrets and webhook HMAC-SHA512 verification keys require 64 bytes for full cryptographic strength. Using shorter keys reduces the effective security of the HMAC.

Root-of-Trust Secrets

Hardware Security Module (HSM) wrapping keys, root encryption keys, and master key material. These protect the entire cryptographic hierarchy of an organization.

Quantum-Resistant Secrets

Forward-looking secrets designed to resist quantum attacks. With 420 bits, Grover's algorithm would still face 210 bits of effective security — far beyond any conceivable quantum computer.

Long-Term Archive Encryption

Encryption keys for data that must remain confidential for 50+ years — medical records, legal documents, trade secrets, and government archives. Maximum key length provides maximum future-proofing.

Password Length vs Security

LengthEntropyCrack Time (GPU)RatingRecommended For
6 chars 39 bits 1.2 minutes Weak temporary or throwaway accounts only
8 chars 53 bits 7.7 days Fair low-security accounts where the site enforces rate limiting
10 chars 66 bits 190 years Good general-purpose accounts and social media
12 chars 79 bits 1.7M years Strong general accounts
14 chars 92 bits 15B years Strong sensitive accounts
15 chars 99 bits 1.5 × 10¹² years Excellent business accounts
16 chars 105 bits 1.4 × 10¹⁴ years Excellent master passwords
20 chars 131 bits 1.1 × 10²² years Overkill master passwords
24 chars 158 bits 9.3 × 10²⁹ years Overkill maximum security
32 chars 210 bits 6.1 × 10⁴⁵ years Overkill encryption keys
48 chars 315 bits 2.7 × 10⁷⁷ years Maximum cryptographic secrets and machine-to-machine authentication
64 chars 420 bits 1.2 × 10¹⁰⁹ years Maximum cryptographic keys

Crack times assume 10 billion guesses/sec (GPU cluster with MD5). Bcrypt/Argon2 hashing makes these 10,000x–100,000x slower.

Other Password Lengths

More Security Tools

🔒

Password Generator

Generate strong, random passwords with customizable length, character sets, and options.

💬

Passphrase Generator

Generate strong, memorable passphrases from random words. Easier to remember, just as secure.

🧠

Memorable Password Generator

Create easy to remember passwords from random words or your own phrases with leet speak conversion.

Bulk Password Generator

Generate multiple unique passwords at once. Perfect for IT admins and account provisioning.

🔑

API Key Generator

Generate cryptographically secure API keys, tokens, and secrets in multiple formats.

📡

WiFi Password Generator

Generate strong, easy-to-share WiFi passwords for your home or office network.

📱

WiFi QR Code Generator

Create a scannable QR code for your WiFi network. Guests connect instantly.

🔓

WiFi QR to Password Converter

Extract the WiFi password from a QR code image. Upload or paste — no camera needed.

🔢

PIN Generator

Generate cryptographically random PIN codes. Perfect for device locks and access codes.

🛡

Password Strength Checker

Test how strong your password is. See estimated crack time, entropy, and suggestions.

🧮

Password Entropy Calculator

Calculate the exact entropy of any password configuration. See bits, combinations, and crack times.

#️⃣

MD5 Hash Generator

Generate MD5 hashes from any text. Useful for checksums, cache keys, and legacy system compatibility.

#️⃣

SHA-512 Hash Generator

Generate SHA-512 hashes using the native Web Crypto API. 512-bit security for signatures and integrity.

Login Barcode Generator

Generate a Code 128 barcode that types username, TAB, password, ENTER into login forms when scanned.

📺

Easy-Type Password Generator

Generate passwords optimized for TVs, game consoles, and devices with on-screen keyboards. No symbols.

🗣

Pronounceable Password Generator

Generate speakable passwords from fake syllables. Easy to say aloud, type from memory, and share verbally.

🌈

Password Generator for Kids

Generate fun, memorable passwords children can actually remember. Word stories: red-panda-jumps-42.

Frequently Asked Questions

Is a 64-character password secure enough?

Yes. A 64-character password drawn from the full 95-character printable ASCII set provides 420 bits of entropy — well beyond what brute-force attacks can crack. It would take 1.2 × 10¹⁰⁹ years to break with current GPU technology. The generator above defaults to a 26-symbol set chosen to avoid characters that break web forms, which gives 413 bits; widen the symbols field to reach the full 95.

How long does it take to crack a 64-character password?

With a modern GPU cluster computing 10 billion hashes per second, a random 64-character password using all character types (95-char pool) would take approximately 1.2 × 10¹⁰⁹ years to crack by brute force. Using only lowercase letters would be significantly faster to crack.

Does character variety matter more than length?

Both matter, but length has a greater impact. Each additional character multiplies the total combinations by the pool size (up to 95 for all printable ASCII). However, using all character types (uppercase, lowercase, numbers, symbols) maximizes the pool size, which also multiplies security exponentially.

Should I use a password manager?

Yes. You cannot reliably memorize unique random passwords for every account. A password manager securely stores all your passwords behind one strong master password, and can auto-fill them across devices and browsers.

Which accounts need a 64-character password?

A 64-character password is recommended for: cryptographic keys, HMAC secrets, and token signing. Always use the strongest password practical for each account, and never reuse passwords across sites.

Password copied!

Let NordPass remember it, so you don't have to.

A strong password only works if you never reuse it — and a notes app isn't storage. NordPass keeps every login encrypted, fills them in for you, and warns you the moment one turns up in a breach.

Get NordPass →
Affiliate link — we may earn a commission at no extra cost to you.