Free online tools to generate, calculate,
convert, format, encode, and play.
 

Passphrase Generator

Generate strong, memorable passphrases from random words. Easier to remember than random characters while providing excellent security. All generation happens locally in your browser using crypto.getRandomValues().


Click "Generate" to create a passphrase
Strength: - Entropy: -
Options
History
Statistics
Word Pool -
Entropy -
Combinations -
Crack Time (10B/s) -
Total Characters -
Tips
  • 4+ words provides strong security for most uses
  • 6+ words for high-security accounts
  • Separators make passphrases easier to type
  • Adding a number or symbol increases entropy
  • Never reuse passphrases across accounts

How It Works

This tool generates passphrases by selecting random words from a curated wordlist using the Web Crypto API (crypto.getRandomValues()). Unlike Math.random(), this provides cryptographically secure randomness. Everything runs entirely in your browser.

Why Passphrases?

Passphrases use multiple random words instead of random characters. The result is a password that is both easier to remember and type, while providing comparable or better security. For example, "Correct-Horse-Battery-Staple" is far easier to recall than "x7$kQ9#mP" yet provides more entropy.

Understanding Entropy

Entropy measures the unpredictability of a passphrase, calculated as log2(pool_size) × word_count. Each word adds roughly 10-11 bits of entropy depending on the wordlist size. Additional numbers and symbols add extra bits.

  • < 40 bits: Very weak - crackable in seconds
  • 40 - 60 bits: Weak - crackable in minutes to hours
  • 60 - 80 bits: Fair - would take days to months
  • 80 - 128 bits: Strong - would take years to centuries
  • > 128 bits: Very strong - practically uncrackable

Word Selection

Words are drawn from a curated list of common English words, filtered by your chosen length range. Using a smaller pool of shorter words makes passphrases more concise, while allowing longer words increases the pool size and entropy per word.

Best Practices

  • Use 4+ words: Four words provides roughly 40+ bits of entropy, sufficient for most online accounts.
  • Use 6+ for high security: Banking, email, and password manager master passwords should use longer passphrases.
  • Add numbers or symbols: Appending a number and symbol adds extra entropy to satisfy strict password policies.
  • Use a password manager: Store your passphrases securely and use unique ones for each account.

Embed This Util

You can embed this util on your own site as a widget. Adding ?embed=1 to the URL loads a compact version with just the tool itself; no header, menu, or documentation. Paste this snippet into your HTML:


    

Copy snippet Adjust the height to taste.



Feedback

Help us improve this page by providing feedback, and include your name/email if you want us to reach back. Thank you in advance.


Share with