Password Policy Validator — Will It Pass Your Rules?
Validate a password against configurable NIST-style rules (length, classes, symbols) plus a common-password blocklist. See exactly what fails. The password NEVER leaves your device. Free.
More tools
All free, all private — everything runs in your browser.
Password Generator
Generate strong, random passwords with configurable length and characters. Powered by WebCrypto, with live entropy shown. 100% in your browser — never transmitted. Free.
Passphrase Generator
Generate memorable 'correct-horse-battery-staple' passphrases from the EFF diceware wordlist. Choose your word count. Strong and easy to type. 100% in-browser. Free.
Pronounceable Password Generator
Generate passwords that are easy to read and say aloud but still strong, built from random syllables with WebCrypto. Easier to remember, hard to crack. 100% in-browser. Free.
PIN Generator
Generate random numeric PINs from 4 to 8 digits for banking, phone, and SIM cards, with WebCrypto randomness. No patterns, no repeats. 100% in-browser. Free.
Bulk Password Generator
Generate dozens or hundreds of strong passwords at once with WebCrypto, then export the batch as CSV, JSON, or .zip. All in your browser — nothing is ever transmitted. Free + Pro.
Password Strength Checker
Check how strong your password really is with zxcvbn real-world scoring, an estimated crack-time, and plain-English tips. The password is NEVER transmitted. 100% in-browser. Free.
How to use Password Policy Validator
- 1Set the rules you want to enforce: length, required character classes, and the common-password blocklist.
- 2Type or paste a password. It's checked locally — never transmitted.
- 3Read exactly which rules pass and which fail.
- 4Adjust the password (or the rules) until it satisfies your policy.
Password Policy Validator FAQ
- What rules can I check against?
- Minimum and maximum length, required character classes (lowercase, uppercase, digits, symbols), and a blocklist of the most common leaked passwords — the core of modern NIST SP 800-63B guidance.
- Does NIST still require complex passwords?
- Modern NIST guidance (SP 800-63B) de-emphasizes mandatory complexity and instead emphasises length and screening against known-breached passwords. This validator lets you model both approaches and see the result live.