Most people open a password generator once, at signup, then never again. That leaves a real gap: the passwords protecting your most important accounts — the ones you set up years ago, before you cared — are usually the weakest ones you have, because nothing ever forced you to revisit them.
Start with your password manager's master password
This is the one password you'll actually type from memory, so it's tempting to make it memorable instead of random. Don't. A 20+ character fully random string, written down once on paper and stored somewhere physical, beats a memorable passphrase you can also guess the pattern of. Everything else in your vault inherits this password's strength as a ceiling.
Sites that reject random strings
Some forms still cap length at 12 characters, block symbols, or require a specific mix that a pure-random generator doesn't guarantee on the first try. For these, generate a passphrase instead — four or five unrelated words strung together. It clears character-mix rules more reliably and is easier to type on a phone if you ever need to enter it manually.
Auditing what you already have
Pull up the accounts you set up more than two years ago — email, banking, your domain registrar. If any password there is something you can recall without your manager's autofill, it's probably reused or pattern-based, and it's worth the ten minutes to regenerate and update it. Old accounts are disproportionately represented in breach dumps precisely because they're old.
API keys and dev tokens
Manually typed test credentials ("test123", a keyboard walk, a project name plus "2024") end up committed to git more often than anyone wants to admit, because a human picked something memorable enough to type twice. A generated token has no meaning to accidentally memorize, and no pattern to grep for across a codebase.
One rule regardless of use case: generate locally, in the browser, not through a site that emails you the result or logs it server-side. If a password ever existed in a network request, treat it as already exposed.