Random PIN generator
Random PIN codes for phones, cards, alarms and door locks, generated on your device. Skips the ones people guess first.
crypto.getRandomValues, never sentWhy PIN length matters more than cleverness
A PIN's safety comes almost entirely from the lockout: a phone that wipes or delays after a handful of wrong attempts, or a card that is blocked after three. With 10,000 four-digit combinations, an attacker who gets five tries has a 1-in-2,000 chance if your PIN is truly random, and much better odds if it's 1234, a year or a date.
Each extra digit multiplies the possibilities by ten. A 6-digit PIN has a million combinations, which is why most phones now default to six. Where a device allows an alphanumeric passcode, a short passphrase is stronger still.
PIN FAQ
How random are these PINs?
Each digit comes from crypto.getRandomValues with rejection sampling, so all ten digits are equally likely in every position. PINs are generated in your browser and never sent or stored.
What does "skip predictable PINs" remove?
It rejects PINs a guesser would try early: all-same digits (1111), straight runs up or down (1234, 9876), repeated pairs (1212), and 4-digit strings that look like a year from 1900 to 2099 or a day-month / month-day date. This costs a little entropy but avoids the top of attackers’ lists.
Is a 4-digit PIN secure?
Only because devices and banks limit attempts. There are just 10,000 four-digit PINs, so a PIN relies entirely on lockout after a few wrong tries. Use 6 digits where allowed; that gives 1,000,000 possibilities.
Should I use my birthday or a memorable date?
No. Dates are among the first guesses because they are easy to find on social media or ID documents, and they cover a small slice of all PINs.