🔤 Text · Updated October 11, 2026 · 5 min read

How to Create a Strong PIN or Passcode (Free, Secure)

Weak PIN Secure PIN 🔢

To create a strong PIN, let a random generator pick the digits, use at least six of them and avoid anything a person could guess: birthdays, 1234, repeats and keyboard patterns. A PIN is short by design, so its strength comes from two other things: randomness, and a lock that stops repeated guessing. GrabCast's free Password Generator has a PIN tab that creates digits with your browser's cryptographic random generator and shows the entropy and how long guessing would take. This guide walks through the numbers with screenshots (13 bits for 4 digits, 20 for 6, 27 for 8) and explains where a PIN is safe and where it is not.

🔢 Try Password Generator now — freeOpen →
Password generator PIN tab with a 6-digit PIN, 20 bits of entropy and the Digits slider at 6
A random 6-digit PIN.
💡 Why PINs are different from passwords

A password protects an account that anyone on the internet can try to enter, so it needs to be long. A PIN usually protects something local, such as a phone, a bank card or a safe, where the device counts wrong attempts and locks or wipes after a few. That changes the math: a 6-digit PIN would fall quickly to a fast offline attack, but the same PIN is reasonable when only a handful of tries are allowed. Knowing which situation you are in tells you how many digits you need.

How much protection each length gives

Each digit multiplies the possibilities by ten. The generator shows the numbers for a random PIN:

The tool labels all three Very weak as passwords, and it adds the important note: PINs are only safe where the device locks after a few wrong tries, never as an online password. Use the longest PIN a device allows and make sure the lockout is switched on.

What makes a PIN easy to guess

People pick PINs that are easy to remember, and attackers try those first: birth years, dates, 1234, 0000, repeated digits, simple sequences and patterns on the keypad. Anything connected to your name, address or phone number is worse. A randomly generated PIN has none of these patterns, so an attacker has no shortcut. The only cost is that you must memorise it, which is why you should pick a length you can hold, ideally six digits, and use it often enough to remember.

Never reuse the same PIN for your phone, your bank card and a door code. If one leaks through a shoulder-surf or a stolen receipt, all of them fall.

Generating one and keeping it safe

Open the PIN tab, set the Digits slider and read the number that appears. The tool uses the browser's cryptographic random source, generates it on your device and sends nothing anywhere. Press the refresh icon for a new one until you get one you can remember; do not keep regenerating until you like the pattern, since that reduces the randomness a little.

Do not store a PIN with the card or device it protects, and do not send it by message. A password manager entry, or your memory, is the place. For accounts on the internet, use a long password or passphrase instead: see how to generate a secure password.

Changing an existing PIN

Change a PIN if you told someone, if it was on a screen while others could watch, or if it is a pattern from the list above. Phones let you set a custom numeric code with six or more digits or an alphanumeric passcode; use the longer option if a stolen phone would expose banking apps. Bank PINs are usually four to six digits and changed at an ATM or through the bank's app. Check the Password Breach Checker for passwords, though a PIN alone does not appear in such lists in a meaningful way.

Choosing between a PIN and a longer passphrase

A short number is convenient for a phone or bank card, but it protects only if the device limits attempts. Online accounts, laptops and anything that can be attacked offline deserve a longer secret. When the system allows letters, a passphrase of several unrelated words is stronger and easier to remember than a long digit string.

For the wider picture, creating a strong password covers random strings and passphrases, remembering strong passwords without reusing them explains safe storage, and the maths of entropy and crack time shows why length matters.

Sharing codes with family members

Door codes, alarm codes and shared device passcodes are easiest to manage when each person has their own. If that is not possible, change the code when anyone moves out, and avoid sending it in a chat. Tell people in person, and review who has access twice a year.

What to do if you forget the code

Most phones and cards offer a reset path, but it usually requires proving who you are. A bank branch can issue a new card code after checking identification, and a phone may need its linked account password. Do not try guesses repeatedly, because lockouts can last longer each time or erase data.

Set up recovery options in advance and keep them current. Store a hint that only you understand, never the code itself, and tell a trusted person where your emergency information is kept.

Step-by-step

1234
1Open the Password Generator and click the PIN tab. Set the Digits slider to 6 (the range is 4 to 12).
Password generator on the PIN tab with a Digits slider set to 6 and a freshly generated PIN
Open the PIN tab and choose how many digits.
2Look at the strength meter: a 4-digit PIN shows 13 bits of entropy and 41 seconds to guess online at 100 tries per second.
A 4-digit PIN with the strength meter reading Very weak, 13 bits of entropy and 41 seconds to guess online at 100 guesses a second
A 4-digit PIN has only 10,000 combinations.
3Move the slider to 8 and watch it become 27 bits and about 7.8 days, so each digit adds real protection.
An 8-digit PIN with the strength meter reading 27 bits of entropy and 7.8 days to guess online at 100 guesses a second
Each extra digit multiplies the combinations by ten.
4Click the refresh icon for a different PIN, memorise the one you choose and enable the device's lockout.

Common mistakes to avoid

⚠️Using a birthday, 1234 or a repeated digit.
⚠️Reusing one PIN on a phone, a card and a door lock.
⚠️Writing the PIN on the card or a sticky note on the device.
⚠️Using a PIN where an account can be attacked online without lockout.

Pro tips

✓Prefer 6 digits or more on devices that allow it.
✓Turn on the auto-lock or wipe after several wrong attempts.
✓Practise a new PIN a few times over two days so it sticks.
✓Use a different PIN for each device and card.
✓For online accounts use a long password or passphrase, not a PIN.

Frequently asked questions

How long should a PIN be?

Use at least six digits where allowed. Four digits offers only 10,000 possibilities, which is fine only when the device locks after a few wrong tries.

Is a random PIN really better than one I choose?

Yes. A random PIN has no patterns for an attacker to try first, unlike birthdays or 1234.

Is the generated PIN sent anywhere?

No. It is generated on your device with the browser's cryptographic random generator.

Can I use a PIN as an online password?

No. Online accounts can be attacked at high speed without a lockout, so use a long password or passphrase.

What are the worst PINs?

Sequences like 1234, repeated digits like 0000, and dates such as birthdays are the first ones guessed.

📌 Bottom line

A strong PIN is random, at least six digits and protected by a lockout. Generate one, check the entropy meter and never reuse it; where there is no lockout, use a long password instead.

Open Password Generator →

Related guides

Browse more: all text and developer guides · Password Generator