Build memorable diceware passphrases: pick 3 to 10 words, a separator, optional number and symbol, and see the entropy and a crack-time estimate.
Passphrases are generated locally with your browser's cryptographic random source. There is no history and nothing leaves the page.
Nothing is stored and there is no history — reloading this page loses what is on screen, so copy what you want to keep.
Diceware came from a 1995 proposal to roll dice over a printed word list; this page keeps the idea and replaces the dice with crypto.getRandomValues. Each of your word slots draws uniformly from the built-in 1,143-word list, contributing about 10.2 bits of entropy, so the default six words give roughly 61 bits before the optional number and symbol add their share. The entropy readout, strength tier and the illustrative crack time update with every generation.
% 1143 would make some words slightly more likely than others — modulo bias. The code computes the largest multiple of the list size that fits in 2^32 and simply redraws values above it. The redraws are cheap and the distribution becomes exactly uniform.Usually yes, because human memory is built for images, not for random symbols. When you generate, keep the lines where each word conjures something vivid — a concrete noun you can picture — and mentally stage the words as a short scene (a penguin polishing a lantern). That is worth more retention than any character gymnastics.
It is the textbook use case. Your vault contents can be long random strings you never type, so the one secret you memorize should be the one you can actually reproduce: five to seven words plus a separator is both memorable and expensive to guess. Pick a passphrase here, type it into your manager once to confirm you remember it, then discard the page.
The selection uses crypto.getRandomValues — the browser's cryptographically secure source — with rejection sampling so every word has exactly equal probability. Security comes from the math: with a list of 1,143 words, each slot contributes about 10.2 bits, so six words already top 61 bits. Nobody can exploit the list because no information about your choice leaves your device.
No, and it would be dishonest to blur the two. A passkey is a public-key credential stored on your device and registered with a website — nothing to memorize. A passphrase is a memorized secret. Passkeys are the better login mechanism where sites support them; a passphrase remains the right tool for master passwords and anywhere you still type secrets.
No. The word list ships inside this page and generation runs entirely in your browser. Nothing is logged, and there is no history: reloading the page loses the passphrase on screen, which is exactly what you want after copying it.
If you just finished with Passphrase Generator, the natural next steps are Password Generator, Password Strength Checker, Morse Code Translator, or browse every tool in Daily Tools.