Passphrase Generator
Several ordinary words, chosen properly — a password you can actually type from memory.
Runs entirely in your browser
Loading tool...
How to use
- Pick how many words — five is a sensible floor for anything that matters.
- Choose a separator your target site accepts; hyphens are safest.
- Generate until you get one you can picture, then use it.
- For a password manager's master password, use six words or more.
Features
- Words drawn with crypto.getRandomValues, using rejection sampling so no word is favoured.
- Entropy in bits, computed from the real list length.
- Hyphen, dot, underscore or space, with optional capitals and a trailing digit.
- Words chosen to be short, common and unambiguous when spoken.
- Runs entirely in your browser — nothing generated here is transmitted or stored.
Frequently asked questions
- Why words instead of random characters?
- Because you have to be able to type it. `Tr0ub4dor&3` is hard to remember and about as strong as three random words; five words from a 512-word list is 45 bits, and six is 54 — with a passphrase you can hold in your head. Where a manager stores the password for you, random characters are better; where a human types it daily, words win.
- Is a passphrase weaker because the words are common?
- No, provided the choice is random. The attacker is assumed to know the word list and the method — that assumption is what makes the entropy figure meaningful. What matters is how many equally likely passphrases there were, not whether the words are obscure. Choosing words yourself is what breaks it, because people do not choose randomly.
- Why does the tool not check the strength of what it produced?
- Because a strength meter reads the output and cannot see how it was chosen. It would score `correct-horse-battery-staple` badly and `P@ssw0rd!` well, and it would be wrong both times. The bits shown here come from the generation method, which is the only thing that determines the answer.
Related tools
Generate strong random passwords.
Measure how many guesses a password would actually take — not whether it has a capital letter.
Draw names out of a hat with a seed anyone can check afterwards.