Security Tools

Passphrase Generator

A passphrase made of several random words is both strong and easy to remember. Choose how many words, what goes between them and how to capitalise them, and generate up to fifty passphrases with your browser’s cryptographic random generator. The page shows the actual entropy, counting only the parts that are random.

  • Runs in your browser
  • No sign-up
  • Free to use

    Words are drawn with your browser’s cryptographic random generator from a list of 1,451 common English words. Nothing is sent or stored.

    How to use Passphrase Generator

    1. Choose the number of words; five or more is recommended.
    2. Pick a separator and a capitalisation style.
    3. Add a number or symbol if a site insists on them.
    4. Generate, choose one passphrase and memorise or store it.

    Passphrase Generator features

    Truly random words

    Each word is picked with crypto.getRandomValues, never Math.random.

    Flexible format

    Hyphens, spaces, dots, random digits or symbols between words.

    Capitalisation

    First letters, one random word or all capitals for sites that demand capitals.

    Honest entropy

    Counts only random choices; predictable formatting adds nothing.

    Batch

    Up to fifty passphrases to pick from.

    Private

    Nothing leaves the page, nothing is saved.

    When to use Passphrase Generator

    • Creating the master password for a password manager.
    • Choosing a disk encryption or Wi-Fi passphrase.
    • Setting a memorable login for a shared family device.
    • Teaching how random word passwords work.

    Passphrase Generator FAQ

    Why are random words secure?

    Because they are chosen at random from a large list. Five words from 1,451 give about 52 bits; the attacker must try a huge number of combinations even knowing the word list and the method.

    How many words should I use?

    Five or six for important accounts, seven or more for a password manager master password or disk encryption.

    Does capitalisation add security?

    Capitalising every word in the same way adds nothing, because the attacker knows the rule. A randomly chosen word in capitals adds a few bits. Extra words add much more.

    Can I choose my own words instead?

    Words people choose themselves are far more predictable. The strength of a passphrase comes from the randomness of the selection.

    Is this the same as Diceware?

    It follows the same principle with a smaller, simpler word list. Diceware uses 7,776 words and real dice; each word there carries 12.9 bits instead of 10.5.

    Is the passphrase stored?

    No. It exists only on this page until you close it.

    Strength people can remember

    The dilemma of passwords is that the strong ones are hard to remember and the memorable ones are easy to guess. Passphrases of random words resolve it. A sequence such as “Maple-Orbit-Grill-Dense-Torch” is easy to picture and recall, yet an attacker who knows the exact method still faces trillions of possibilities.

    The security comes from the random selection, not from the words being obscure. That is why the generator uses common, short words: they are easy to type and remember, and the strength is calculated honestly from the size of the list and the number of words. Each additional word multiplies the attacker’s work by the size of the list.

    Formatting choices are mostly about meeting site rules. Some sites require a digit, a symbol or a capital letter; the options here satisfy them in ways that add a little real randomness, and the entropy figure shows exactly how much. Predictable formatting, such as capitalising every word, is counted as zero, because attackers can apply the same rule.

    A passphrase is ideal for the few secrets you must type from memory: the password manager, the computer login, disk encryption. Everything else should be a long random password stored in the manager. Never reuse a passphrase between services.

    Other useful tools