Archive password preset

ZIP Password Generator

Create a strong random password to use with an encrypted ZIP or 7z archive. Pick a compatibility profile, copy the result, and add it in your archive software.

Generate an archive password

The default creates a 32-character password for a modern AES-encrypted archive. This tool generates the password only.

Maximum compatibility uses letters and numbers without look-alike characters.
32
Compatibility options
Quotes, backslashes, and backticks are always excluded to make copying into archive apps and commands less error-prone.

Calculating randomness32 characters
Password generated locallyNo archive or file is selected, uploaded, read, or changed by this page.

How to use the generated ZIP password

Copy the result into the password or encryption field in your archive application. Enter it again when prompted, save it in a password manager, then test extraction before deleting the unencrypted source files.

Use modern AES encryption when possible

ZIP software can offer multiple encryption methods. 7-Zip supports AES-256 in ZIP and 7z archives, while WinZip documents AES-128 and AES-256 support. Legacy Zip 2.0 encryption—often called ZipCrypto—is designed for compatibility and is substantially weaker. The password cannot upgrade a weak encryption method, so check the archive application's encryption setting as well as the password.

Why the default is 32 characters

A random 32-character password drawn from letters, numbers, and symbols has a large search space and is practical to store in a password manager. WinZip's password guidance also emphasizes length and mixed character types. The 64-character profile is available for workflows that accept a very long value; it is not a claim that the resulting archive achieves 256 bits of password-derived security.

AES-256 does not mean every password has 256 bits

AES-256 names the cipher's key size. Archive software derives an encryption key from the password using a key-derivation process and stored salt. A short or predictable password remains guessable even when the archive label says AES-256. Use a fresh random result rather than a name, birthday, phrase from a song, or reused account password.

Choose compatibility intentionally

The maximum-compatibility profile uses 24 letters and numbers, removes characters that are easy to confuse, and avoids punctuation. It can be easier to enter across phones, keyboards, and older archive tools. For a modern desktop archive workflow, the 32-character AES profile adds symbols and is the stronger default.

Send the password separately

Do not attach the archive and place its password in the same email or message. Share the archive through one channel and the password through another approved channel. Remember that filenames and other archive metadata may still be visible, depending on the format and options selected.

Do not lose the only copy

Archive vendors warn that an encrypted file cannot be recovered without the correct password. Store it before closing the archive application and test it on a copy. For long-term storage, document the archive format, encryption method, and extraction software as well as the password.

References and related tools

See 7-Zip's supported formats and AES-256 feature, WinZip's AES ZIP specification, and WinZip's encryption overview. For another output format, use the password generator, passphrase generator, or random key generator.