MorphPass.

YOUR EVERYDAY RANDOM GENERATOR

Random.
On your terms.

Custom password generation with exact character counts, exclusions and batches. Understand the rules here, then configure and generate inside the separate ad-free tool.

Generate

Generator launch is pending. This is the planned destination; it may not resolve yet. Opens the separate ad-free tool in a new tab.

START WITH RULES, NOT A PATTERN

What exact counts actually change

The Password preset starts at 20 characters, with uppercase, lowercase, numbers and symbols selected and at least one from each required. Exact counts is optional: the length becomes the sum of your four counts and the positions are shuffled. A count of 0 leaves that group out. It does not make characters alternate or put symbols at the end.

Every example string here is fictional and public. Never use one as a real password. These examples illustrate valid shapes, not strings the tool promises to produce.

1. A 20-character format

Choose Password, enable exact counts and enter 6 uppercase, 6 lowercase, 6 numbers and 2 symbols. Their sum is 20. Leave exclusions empty for this example.

Fictional example — unsafe for real use

ABcd12!EFgh34?IJkl56
Check this example

The capitals are A, B, E, F, I and J; the lowercase letters are c, d, g, h, k and l; the numbers are 1–6; the symbols are ! and ?. This deliberately grouped illustration makes counting easy. Real positions are shuffled, and repeated characters are allowed.

2. Exact counts plus exclusions

For a short demonstration, request 2 of each group, turn on Skip look-alike characters and exclude @&. The length stays 8.

Fictional example — unsafe for real use

Az7!Bm8?
Check this example

It has two of every group and none of I l 1 O 0 o | or @&. Exclusions remove choices; they do not reduce quotas. Eight characters illustrates the rule, not a recommendation for an account password.

3. Letters and numbers only

Choose Alphanumeric and exact counts: 4 uppercase, 4 lowercase, 4 numbers, 0 symbols. The total is 12. Keep Symbols at 0 for a letters-and-numbers-only format.

Fictional example — unsafe for real use

Ab1Cd2Ef3Gh4
Check this example

Preset defaults are a starting point; your exact quotas determine the groups. A short reference code can collide with another code. MorphPass does not reserve IDs or keep a uniqueness registry.

4. A custom alphabet

Choose Custom alphabet, enter AABC12, exclude C2 and choose length 6. Duplicate letters count once, so the remaining choices are A, B and 1.

Fictional example — unsafe for real use

AB1BA1
Check this example

Each position is drawn from those three characters, and repeats are normal. Custom mode accepts visible ASCII characters without spaces, not emoji or accented alphabets. It has no exact-group-count option. This tiny alphabet and short result are unsuitable for account passwords.

When settings conflict

If no result can meet the rules, change the settings instead of repeatedly pressing Generate. Any setting change clears the previous result and disables Copy until you generate again.

Expected behavior in the current generator
SettingsWhy it failsWhat to change
All exact counts are 0Total 0 is rejected; the total must be 1–128.Give at least one group a positive count.
Counts 127 / 1 / 1 / 0Total 129 is rejected even though each individual count is within range.Reduce the total to 128 or fewer.
A blank, negative or fractional countEach count must be a whole number from 0–128.Use an integer; use 0 to omit a group.
2 / 2 / 2 / 2; exclude 0123456789No numbers remain for the positive number quota.Allow a number or set its count to 0. With 2 / 2 / 0 / 2, the new total is 6.
Simple mode, length 3, all four groups selected and requiredThree positions cannot contain four required groups.Increase length or adjust groups or the requirement.
Custom alphabet AAB; exclude BOnly A remains; at least two different available characters are required.Restore another choice. Increasing length alone will not fix it.

Length is 1–128 and quantity is 1–100. A permitted value is not automatically suitable for a password. Selecting a preset returns to simple mode and its default counts. In exact mode, the ordinary group checkboxes and “at least one” option do not determine quotas.

How the browser chooses characters

MorphPass uses crypto.getRandomValues, the browser’s cryptographic random source. It fails if secure randomness is unavailable; it does not fall back to Math.random. This is an explanation of the implementation, not certification of your browser or device.

Equal chances, without rounding bias

A random byte has 256 possible values. Ten number choices do not divide 256 evenly: reducing every byte modulo 10 would favor six numbers. For ten choices, MorphPass accepts 0–249, giving 25 byte values to each number, and rejects 250–255 before drawing again. Other choice counts use the same rejection principle.

Two ways to meet the rules

Simple mode builds a whole candidate. With every selected group required, it discards candidates missing a group and tries again. Exact mode draws the requested number from each filtered group, then shuffles with Fisher–Yates: each position swaps with an unbiased random choice among the remaining positions.

Exact quotas narrow the possible combinations compared with unrestricted choices from the full alphabet. Including four groups cannot rescue a very short password. There is no strength score or collision guarantee. Very restrictive simple-mode settings can reach the retry limit; the tool asks you to increase length or relax the group requirement.

The local checks cover rejection sampling, exact quotas, exclusions, small shuffle permutations and failure when randomness is unavailable. They are bounded implementation checks, not an independent security audit. See browser randomness documentation.

From a generated result to an account password

  1. Start with the destination’s rules. Keep the 20-character Password default when the service accepts it. Change length and exclusions as needed; sites differ in supported symbols and maximum lengths.
  2. Use a fresh, different password for each account. A leaked reused password can expose other accounts, even if it was originally random. Store each value in a password manager instead of reusing a memorable pattern.
  3. Copy the current result. Copy becomes Copy all for a batch and writes one result per line. If copying is unavailable, the tool selects the output for manual copying. Check the intended password field, not a public chat or support message.
  4. Understand Clear. It removes displayed results, not clipboard history, device synchronization or copies saved elsewhere. It cannot promise erasure of browser memory.

The page code does not transmit generated strings or save a result history. Extensions, compromised devices, clipboard retention, phishing and a service’s password handling remain outside its control. Hosting may log ordinary page requests. No password guarantees account security.

RESEARCHED OCTOBER 4, 2026

How passwords get compromised, and what you can do

Did you know? In Verizon’s 2026 Data Breach Investigations Report, credential abuse was the first identifiable way in for 13% of the non-Error, non-Misuse breaches it analyzed. But Verizon adds: “if you consider all instances of credential abuse at any point in the breach progression, it still sits on top at 39%.” The figure behind that statement covers 19,905 breaches. The report’s analysis window was Nov 1, 2024, to Oct 31, 2025. These are organizational breaches worldwide, not a count of individual US victims. Verizon 2026 DBIR, page 16; analysis window, page 9.

A password can be exposed without someone guessing every character. Here are five common routes and practical responses. They are not a ranked list, and more than one can be involved in the same account takeover.

Reusing a password

Attackers try username/password pairs leaked from one service against others. This is credential stuffing: even a long, random password loses its advantage if you reuse it after a leak. Give each account a different password and keep them in a password manager. That limits how far one exposed credential can travel. Verizon’s credential-stuffing research.

Choosing predictable patterns

Familiar words, personal details and small variations are easier to anticipate than independent random choices. Aim for 16 characters or more where the service allows it; MorphPass starts at 20. Adding a symbol is not a magic fix. Use length and randomness, and change a compromised password rather than relying on calendar-based rotation. CISA’s password guidance; NIST password guidance.

Entering it on a phishing page

A convincing message can lead to a fake sign-in page that collects a perfectly good password. Don’t use a login link in an unexpected message. Open the service yourself through a bookmark, its app or an address you type. When supported, passkeys provide phishing-resistant sign-in. A random password generator cannot tell whether a page asking for your password is genuine. NIST phishing guidance; FIDO passkeys.

Malware stealing credentials or sessions

Infostealer malware can take “financial credentials, cryptocurrency wallets, browser extensions, and multifactor authentication (MFA) details” from an infected computer, according to the FBI and CISA. Stolen session cookies may also let an attacker access an already authenticated session without repeating the normal password or MFA check. Keep software updated, avoid unexpected downloads, and never paste commands into a terminal or Run window just because a “CAPTCHA” tells you to. FBI/CISA infostealer advisory; FBI session-cookie warning.

A service’s password database being breached

Stolen password hashes can be attacked offline; the service’s storage protections matter alongside your password choice. Change affected passwords and any reused copies. Review recovery details and active sessions, and remove malware from a suspected compromised device before trusting new credentials to it. Use the service’s recovery process if you have lost access. NIST on offline attacks; FTC recovery steps.

What MorphPass helps with

MorphPass uses browser cryptographic randomness and offers exact counts and exclusions for a service’s format rules. It does not save a password history. It cannot prevent phishing, remove malware or fix a breached service. Enable MFA or use passkeys where available, alongside unique passwords and device care; none of these measures stops every attack.

If you suspect an account takeover, start with the provider’s recovery instructions. Secure the email account used for resets and check unfamiliar recovery information or signed-in devices before moving on to other accounts. FTC account recovery guidance.

GUIDES

Practical password guides

Questions about the actual tool

Can exact counts work with a custom alphabet?

No. Exact group counts are available in Password and Alphanumeric presets. Custom mode samples from your deduplicated, filtered alphabet without group quotas.

Can characters or entire results repeat?

Yes. Repeated characters and duplicate results are allowed. A batch is not guaranteed to contain unique strings, and MorphPass cannot check whether a code was used elsewhere.

Does skipping look-alikes remove every confusing pair?

No. It currently removes I, lowercase l, 1, O, 0, lowercase o and |. Fonts can make other characters look similar. Add your own exclusions for a particular format.

Do exclusions change the length?

No. They remove choices before sampling. An exact quota stays the same, so a positive quota needs at least one character left in that group. Selection then applies to the remaining choices.

Can this issue recovery codes or API keys?

It creates random strings. Recovery codes and API keys normally must be issued and registered by the service that validates them. MorphPass cannot register a value, make it a valid key or grant access permissions.

Where will the advertising go?

The plan is Google AdSense ads on this information site’s guide pages only, after Google approves the site. The separate generator stays free, with no ads, analytics or other third-party scripts. No ad code is installed in this copy. The privacy page describes the advertising cookies and the consent banner for visitors in the EEA, UK and Switzerland. Approval and revenue are not guaranteed. Your settings stay inside the tool and are never passed in the Generate link.