Passphrase generator — strong, memorable random passphrases
Generate a secure passphrase from the standard EFF word list (7,776 words) using cryptographically secure randomness. Every word is chosen on this device — the passphrase you generate is never sent to a server, logged, or stored anywhere.
Generate a passphrase
Your passphrase
Copy or download it now — it is not stored anywhere and cannot be recovered after you leave this page.
How it works
Three deterministic steps, all computed in this tab:
- Pick words. Each word is chosen uniformly from the EFF large wordlist (7,776 common, easy-to-spell words) — the same list used by many Diceware-style tools. Words are drawn without replacement, so a word never repeats inside one passphrase.
- Use real randomness. The index into the word list
comes from
crypto.getRandomValueswith rejection sampling, which removes modulo bias. This is cryptographic-grade randomness, notMath.random(). - Estimate strength honestly. Each word from a 7,776-word list contributes log₂(7,776) ≈ 12.9 bits of entropy. Because words are drawn without replacement, a six-word passphrase has about 77.5 bits — the estimate shown on the page uses exactly this calculation.
Worked example: with six words and hyphens you might
get jigsaw-bunker-sunrise-quill-tango-zephyr — easy to
type, easy to remember, and far stronger than a short
character-jumble password.
Why passphrases beat short passwords
Password-cracking tools work by guessing: short, predictable passwords fall to dictionary and brute-force attacks in seconds or minutes. A passphrase's strength comes from length plus randomness — a long string of random words has a huge search space while remaining practical to type on phones, TVs, and keyboards. The trade-off is real: use a passphrase that is random (not a quote or song lyric), unique per account, and stored safely.
When should you use a passphrase?
A passphrase is not the right answer everywhere — but it is the practical answer in several common situations:
- Master passwords and vault keys. The one secret that protects everything else deserves the strongest form you can still type from memory. A phrase you enter constantly is where a passphrase's memorability pays off most.
- Disk and file encryption. LUKS, BitLocker, FileVault, PGP, and SSH keys all accept long passphrases, and their security guidance has recommended them for years. A six-word phrase is stronger and easier to type than the short passwords many people fall back to.
- Devices and accounts you sign into by hand. Smart TVs, game consoles, shared workstations, and public terminals rarely have a password manager available. A phrase you can type from memory beats a random 16-character string you will have to look up or reset.
- Recovery and legacy accounts. For a rarely used recovery email or an old site that insists on a password, a unique, memorable passphrase is the practical way to avoid reusing a password you care about elsewhere.
Passphrase vs password: the honest comparison
A six-word passphrase and a 12-character random password are roughly equal in strength. The real difference is how they behave in daily use:
| Consideration | Six-word passphrase | 12-character random password |
|---|---|---|
| Typical example | jigsaw-bunker-sunrise-quill-tango-zephyr | K7#p2!xQ9mR4 |
| Strength | ≈ 77.5 bits of entropy | ≈ 78.8 bits of entropy |
| Memorability | Six ordinary words — easy to recall | Random characters — hard to recall |
| Typing on phones and TVs | Comfortable, few typos | Error-prone, shift-key heavy |
| Sites that cap length | May not fit a 20-character limit | Fits typical 12–16 character limits |
| Main risk | Reusing one, or picking a quote or lyric | Reusing one, or writing it down |
Worked example: a six-word passphrase drawn from the 7,776-word list is worth log₂(7,776) ≈ 12.9 bits per word — about 77.5 bits in total, roughly the same strength as a 12-character random password (log₂(95¹²) ≈ 78.8 bits). The difference is that the words are something you can actually remember and type, which is why passphrases are the recommended choice for master passwords and encryption keys.
Limits
- Not a password manager: this tool generates a random secret and displays it once. It does not store, sync, or autofill passphrases — keep the copy you made somewhere safe.
- Entropy assumes true randomness: the estimate is exact only if your device's random source is working correctly and the options stay as chosen. Re-using a generated passphrase across sites undoes its strength.
- No guarantee of uniqueness: any random generator can in principle repeat an output. Check passphrase strength and uniqueness with your own tools if the account is critical.
- Word list: EFF large wordlist by the Electronic Frontier Foundation, CC BY 3.0.
Frequently asked questions
What is a passphrase and why use one?
A passphrase is a password made of several random words, such as 'correct-horse-battery-staple'. Because each word contributes roughly 12.9 bits of entropy, a six-word passphrase from a 7776-word list has about 77 bits of strength while staying far easier to type and remember than a random jumble of characters.
Are my generated passphrases sent anywhere?
No. This is a static page: the word list is loaded into your browser and every random choice is made on your device. Generated passphrases are never sent to a server, logged, or stored — you can refresh or close the tab and nothing remains.
How is the randomness generated?
The page uses the Web Crypto API
(crypto.getRandomValues) with rejection sampling,
which produces a uniform, unbiased index into the word list. This
is the same class of randomness used for keys and tokens, and is
stronger than Math.random(), which is not designed
for secrets.
Is a generated passphrase enough to secure my account?
Strength is only part of the picture. Use a unique passphrase per account, store it in a password manager if you use one, and keep your devices updated. This tool generates a random secret; it does not manage, store, or sync passphrases for you.
How many words should a passphrase have?
Four to six words (roughly 51 to 77 bits of entropy) is a sensible range for most accounts: strong enough for online services while staying easy to type. Go longer — six to eight words — for high-value secrets such as a password-manager master password or an encryption key. This tool allows 3 to 12 words and shows the exact entropy estimate for your choice.
What if a website won't accept spaces or long passphrases?
Some sites cap passwords at 12 to 16 characters or reject spaces. For those accounts, generate a shorter passphrase (four words with a hyphen separator fits in roughly 26 characters) or let a password manager create a random password for that one site. The separator options on this page — hyphen, period, or none — exist precisely for these cases. Prefer services that accept long passphrases, and keep every passphrase unique to its account.
Related tools
- Date Calculator — count days and business days between dates, or add and subtract days.
- Document Hygiene — inspect and scrub metadata from documents and photos before sharing them.
- Text Hygiene — inspect invisible Unicode characters and review writing patterns locally.
- RAG Cleaner — clean text and HTML into deterministic Markdown and chunks, browser-local.
- Media Optimizer — resize and compress images in your browser.
- Time Coordinator — plan schedules across time zones with DST-aware local times.
- Payload Workbench — inspect and transform JSON and Base64 payloads locally.
- Subtitle Converter — convert SRT and VTT subtitle files locally.
- Volumetric Weight Calculator — calculate chargeable weight for courier and freight shipments.
- Bingo Card Generator — make free printable bingo cards for 75-ball, 90-ball, or word games.
- CBM Calculator — estimate cubic meters (CBM) and container fit for sea-freight shipments.
- Color Contrast Checker — check the WCAG contrast ratio between two colors with AA/AAA verdicts.
- Freight Class Calculator — estimate the NMFC freight class from pallet dimensions and weight (standard LTL density scale, classes 50–500).
Part of Local Toolworks. Last reviewed: 2026-08-16.