Skip to content
MoneyDeck

Passphrase Generator

Create strong, memorable multi-word passphrases with the entropy shown

Updated · Free, no signup

7+ words is strong; 8+ is very strong.

Adds about 6.6 bits and satisfies "must contain a digit" rules.

A seed makes the result reproducible — never use a seeded passphrase for a real account.

Your passphrase

pulse-toy-whistle-apple-saga-plaza-oxygen

More options

fountain-panther-attic-hobby-orchard-ethic-sunset
bubble-stamp-dozen-delta-table-drill-monk

Entropy

67.2 bits

Strength

Strong

Average time to crack

28 years

Offline attack at 100 billion guesses per second.

Possible passphrases

1.74 × 10^20

Words in list

779

  • Each word adds 9.61 bits because it is one of 779 equally likely choices.
  • Add 1 more word(s) to pass 75 bits — recommended for a master password.

About the Passphrase Generator

This passphrase generator strings together randomly chosen everyday words — like "maple-otter-lantern-quiz-cobalt" — to make passwords that are long, strong and far easier to remember or type than a jumble of symbols. It works like the Diceware method: each word is picked uniformly at random from a fixed list, so the strength can be measured exactly in bits of entropy.

Use it for a password manager master password, full-disk encryption, Wi-Fi keys, or any account where you must type the password yourself. Choose the number of words, the separator, capitalization and an optional two-digit number to satisfy sites that insist on digits. The tool shows the entropy, the number of possible passphrases and how long an offline attacker would need to guess it.

Words are drawn with your browser's cryptographically secure random generator and nothing is sent anywhere. Only use the optional seed for demonstrations: anyone who knows the seed can reproduce the passphrase.

How to use the passphrase generator

  1. 1Choose how many words you want — 7 or more for important accounts.
  2. 2Pick a separator and whether to capitalize words or add a number.
  3. 3Leave the seed blank so the words come from the secure random generator.
  4. 4Pick one of the generated passphrases and store it in your password manager.
  5. 5Practice typing it a few times so it sticks.

Formula and method

Entropy (bits) = W × log₂(N) [+ log₂(100) with the number] Time = 2^(H−1) ÷ G

Every word is chosen independently and uniformly from a list of N words, so a W-word passphrase has N^W possible values and W × log₂(N) bits of entropy. Adding a random two-digit number multiplies the possibilities by 100 (about 6.6 more bits). Capitalization and the separator are fixed choices you make, so they add no entropy if an attacker knows your settings.

The average crack time assumes the attacker knows the exact method and word list and must search half of the 2^H possibilities, at G = 100 billion guesses per second — a realistic rate for a GPU cluster attacking a fast, unsalted hash. Slow hashes like bcrypt or Argon2 make real attacks far slower.

W
Number of words
N
Size of the word list
H
Entropy in bits
G
Attacker guesses per second (10¹¹)

Worked examples

Default 7-word passphrase

Seven words from a 779-word list give 7 × log₂(779) ≈ 7 × 9.605 = 67.2 bits. An attacker must try about 2^66.2 guesses on average; at 100 billion per second that takes around 28 years.

Short 5-word phrase with a seed

Five words carry about 48 bits — fine for a low-value login protected by rate limiting, but an offline attacker at 100 billion guesses per second would need only around 24 minutes on average. The seed "correct horse" reproduces this exact phrase, which is why seeds are for demos only.

8 capitalized words plus a number

Eight words give 76.8 bits and the two-digit number adds log₂(100) ≈ 6.6, for 83.5 bits in total. Even at 100 billion guesses per second, the average search would take about 2.1 million years.

Frequently asked questions

Is a passphrase better than a complex password?+

For passwords you type yourself, usually yes. Seven random words carry about as much entropy as a 10-character random password using letters, digits and symbols, but are much easier to remember and type correctly.

How many words should my passphrase have?+

With this 779-word list, 7 words (about 67 bits) is strong for most accounts, and 8 or more words (about 77 bits or more) is recommended for a password manager master password or disk encryption.

What is Diceware?+

Diceware is a method where you roll five dice to pick each word from a 7,776-word list, giving 12.9 bits per word. This tool uses the same idea with a computer's secure random generator and a shorter list of simpler words.

Does capitalizing words make it stronger?+

Only slightly, and only if the attacker does not know you did it. Capitalizing every word is a predictable rule, so the entropy count ignores it. Adding more random words is far more effective.

Is it safe to generate a passphrase in the browser?+

Yes. Words are chosen locally with crypto.getRandomValues and nothing is sent to a server. Avoid the seed option for real accounts, because anyone with the same seed gets the same passphrase.

Related tools