Credential field manual · 6 min read

How long should a password be?

For an online account, 20 randomly generated characters is a practical starting point when the service accepts it. Use a different password for every account, save it in a password manager, and enable multi-factor authentication (MFA). This is our practical recommendation, not a universal minimum or a guarantee against compromise.

A long phrase you invent yourself is not equivalent to the same number of randomly selected characters. How the password is generated matters as much as its length.

Choose a length for your situation

Use Practical starting point Check before saving
Online account 20 random characters The service’s length and character rules
Symbols are not accepted 20–24 random letters and digits Maximum length and required character types
Password-manager master credential At least 6 independently selected random words The product’s guidance and recovery plan
Home Wi-Fi 20–24 random characters Router and client-device compatibility
Device unlock PIN 6 or more random digits where supported Device-enforced attempt limits

These are starting points, not requirements imposed by NIST on Wi-Fi, password managers, or every device. A device unlock PIN is not a substitute for an account password.

Use the random password generator, letters-and-numbers generator, or random passphrase generator for the format your service accepts.

What NIST actually requires

NIST SP 800-63B-4, Password Verifiers distinguishes requirements from recommendations for services verifying passwords:

  • Single-factor passwords: services must require at least 15 characters.
  • Passwords used only as part of MFA: services may allow shorter passwords, but must still require at least 8 characters.
  • Maximum length: services should permit at least 64 characters. This is a recommendation, not a claim that every website accepts 64.
  • Composition and rotation: services must not impose arbitrary character-mixing rules or routine periodic changes. A change is required when there is evidence of compromise.
  • No truncation: the verifier must check the complete submitted password.

An 8-character MFA minimum is not our suggested target. A passkey is a different authentication method, not an 8-character password.

How length changes the search space

For independent, uniformly random selections, the theoretical entropy is:

Entropy in bits = length × log₂(character-pool size).

Random format Pool size Theoretical entropy
12 letters and digits 62 71.5 bits
16 letters and digits 62 95.3 bits
20 letters and digits 62 119.1 bits
24 letters and digits 62 142.9 bits
20 printable non-space ASCII characters 94 131.1 bits

The 94-character row is an illustrative full ASCII pool, not the exact symbol set of every generator. Our tools use selected character sets and can require at least one character from each set; their displayed pool-based entropy is an estimate, not an exact measurement of the output distribution.

These figures do not apply to names, quotations, keyboard patterns, or a password followed by a predictable year. Read how to create a strong password for those distinctions.

Why there is no universal time-to-crack table

Offline guessing speed depends on the password hash, its cost settings, the attacker’s hardware, and the guessing strategy. Online login attempts may be rate-limited instead. A single “years to crack” number hides these assumptions and can be misleading.

Adding random characters increases resistance to guessing. It does not prevent phishing, malware, password reuse, or someone reading a shared password. No finite password should be described as mathematically unbreakable.

How long should a Wi-Fi password be?

For a home network that accepts it, start with 20–24 random characters, using a different credential from the router administrator login. Follow the router’s own accepted length and character rules, and check older devices before changing the network.

The shortest password a setup screen accepts is a compatibility limit, not a security target. Do not apply NIST’s web-account length rules as if they were a WPA2 or WPA3 specification. If a device cannot accept your chosen format, follow its manufacturer guidance and use the longest practical unique random password it supports.

The Wi-Fi password generator can create a new key and QR code. Save that exact key in your router first: generating a code does not change the router’s settings.

What about a password I need to remember?

Use independently generated words rather than inventing a sentence. Our word tools use the 7,776-entry EFF Long Wordlist: six independent selections provide about 77.5 bits before any additional random choices. Fixed capitalization or separators do not add randomness.

See passphrase vs. password for the trade-off between typing, length, and generation method. Store recovery information securely according to the service’s instructions.

What if a website limits password length?

Use a unique random password within its stated limit. Do not reuse another account’s password or assume a longer value will be stored without truncation. Enable MFA or a passkey if available.

For sites that reject punctuation, our password generator without symbols offers 12–64 characters. The target website’s policy still takes priority.