password-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@password-mcpgenerate a 20-character password with symbols and no ambiguous characters"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
password-mcp
MCP server: generate strong passwords and score password strength with
zxcvbn. Randomness comes from Node's crypto.randomBytes with rejection
sampling so the distribution is uniform across the chosen alphabet.
Tools
generate
{ "length": 20, "exclude_ambiguous": true }→ { "password": "aB3xK7nQ2wP9vR4zM8tL" }
Field | Default | Notes |
| 20 | 4-256 |
| true | |
| true | |
| true | |
| true | |
| false | Drops |
At least one character from each enabled class is guaranteed.
strength
{ "password": "correct horse battery staple" }→
{
"score": 4,
"guesses_log10": 17.34,
"crack_time_display": "centuries",
"warning": "",
"suggestions": []
}score is the zxcvbn 0-4 strength rating. guesses_log10 is the base-10 log
of the estimated guesses needed.
Related MCP server: MCP Password Generator
Configure
{ "mcpServers": { "password": { "command": "npx", "args": ["-y", "@mukundakatta/password-mcp"] } } }License
MIT.
Available Tools
2 toolsgenerateA
Generate a cryptographically random password. Enable lowercase/uppercase/digits/symbols (defaults: all on). Length 4-256.
| Name | Required | Description | Default |
|---|---|---|---|
| length | No | ||
| lowercase | No | ||
| uppercase | No | ||
| digits | No | ||
| symbols | No | ||
| exclude_ambiguous | No | Drop 0/O/1/l/I/| etc. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description bears full responsibility. It states 'cryptographically random,' which is a key behavioral trait, but does not disclose other aspects like performance, permissions, or handling of invalid parameter combinations (e.g., all flags false).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two concise sentences that are front-loaded: the first states the core purpose, the second adds essential details. No unnecessary words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given 6 parameters and no output schema, the description lacks information on return format (the generated password as a string). It also does not explain edge cases like conflicting flags or how exclude_ambiguous works beyond the schema's brief description.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is only 17% (only exclude_ambiguous has a description). The description adds value by explaining that the boolean flags enable character types and defaults are all on, and length range 4-256. However, it does not detail each parameter beyond what is obvious from property names.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool generates a cryptographically random password. It specifies the character types (lowercase, uppercase, digits, symbols) and length range (4-256), making the purpose unambiguous. It distinguishes from the sibling 'strength' by focusing on generation rather than analysis.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage (generating passwords) but provides no explicit guidance on when to use this tool versus the sibling 'strength' or when not to use it. No alternatives or exclusions are mentioned.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
strengthA
Score a password with zxcvbn. Returns score 0-4, guesses_log10, human crack-time, and feedback.
| Name | Required | Description | Default |
|---|---|---|---|
| password | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must disclose behavior. It states that the tool scores a password and returns specific metrics, implying a read-only operation with no side effects. However, it could explicitly confirm no mutation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single concise sentence that front-loads the primary action and lists return values. Every word is necessary and efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple tool with one parameter and no output schema, the description adequately covers the return fields (score, guesses_log10, etc.). However, it does not detail the structure of the feedback object, which could be helpful.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must add value. It mentions 'password' as the input but does not elaborate on format, constraints, or other requirements beyond what the schema indicates. Minimal additional context.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool scores a password with the zxcvbn algorithm and lists the return values (score 0-4, guesses_log10, human crack-time, feedback). It distinguishes itself from the sibling tool 'generate' which likely creates passwords.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage for password strength checking but provides no explicit guidance on when to use this tool versus alternatives, nor does it mention any preconditions or limitations.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
TDQS
The two tools have completely distinct purposes: one generates passwords, the other evaluates their strength. There is no overlap or ambiguity.
The names are simple and clear, but one is a verb ('generate') and the other is a noun ('strength'), which is a minor inconsistency. A more consistent pattern would be 'generatePassword' and 'checkStrength'.
Two tools is appropriate for a focused password utility: generation and strength assessment. No extraneous tools, and the scope is well-defined.
The tool set covers the core password operations: generation and strength evaluation. It is missing features like hashing or breach checking, but the scope is reasonable for a minimal MCP server.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Generate IDs, QR codes, and hashes, encode values, geolocate IPs, plus gated host diagnostics.
Hash passwords with bcrypt and issue/verify JWT session tokens over A2A + MCP.
Related MCP Servers
- AlicenseAqualityDmaintenanceProvides random number generation utilities, including a secure UUID generator powered by Node's crypto module.7213MIT
- FlicenseNot gradedqualityDmaintenanceGenerates secure random passwords and memorable passphrases with customizable options including length, character types, emojis, and automatic strength evaluation using zxcvbn scoring.
- FlicenseNot gradedqualityDmaintenanceCryptographically secure random number generation and randomized resources, including tools for numbers, strings, dice rolls, UUIDs, and passphrases.4
- AlicenseNot gradedqualityAmaintenanceLocal, encrypted password vault with AES-256-GCM and PBKDF2, exposing MCP tools for secure credential management, password generation, and search.MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/MukundaKatta/password-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server