Passphrase Generator

Build memorable diceware passphrases: pick 3 to 10 words, a separator, optional number and symbol, and see the entropy and a crack-time estimate.

Passphrases are generated locally with your browser's cryptographic random source. There is no history and nothing leaves the page.

Press Generate
—

Nothing is stored and there is no history — reloading this page loses what is on screen, so copy what you want to keep.

How It Works

Diceware came from a 1995 proposal to roll dice over a printed word list; this page keeps the idea and replaces the dice with crypto.getRandomValues. Each of your word slots draws uniformly from the built-in 1,143-word list, contributing about 10.2 bits of entropy, so the default six words give roughly 61 bits before the optional number and symbol add their share. The entropy readout, strength tier and the illustrative crack time update with every generation.

Why rejection sampling, not modulo
A 32-bit random integer is not evenly divisible by 1,143, so % 1143 would make some words slightly more likely than others — modulo bias. The code computes the largest multiple of the list size that fits in 2^32 and simply redraws values above it. The redraws are cheap and the distribution becomes exactly uniform.
Why length beats complexity
Guessing cost grows with the size of the space, not the number of symbol categories. Requiring Tr0ub4dor&3 instead of four random words typically shrinks the space, because humans fit the requirement into familiar templates. Word slots multiply the space by 1,143 each — add words instead of pain.
Where the crack time comes from
The page shows half the search space divided by 10^12 guesses per second — a generous modern GPU-plus-cluster rate for a badly stored hash. It is arithmetic, not marketing: well-hashed passphrases are effectively unguessable long before the number gets astronomical.

Frequently Asked Questions

Will I actually remember a passphrase?

Usually yes, because human memory is built for images, not for random symbols. When you generate, keep the lines where each word conjures something vivid — a concrete noun you can picture — and mentally stage the words as a short scene (a penguin polishing a lantern). That is worth more retention than any character gymnastics.

Is a passphrase good as a password-manager master password?

It is the textbook use case. Your vault contents can be long random strings you never type, so the one secret you memorize should be the one you can actually reproduce: five to seven words plus a separator is both memorable and expensive to guess. Pick a passphrase here, type it into your manager once to confirm you remember it, then discard the page.

Is a built-in word list random and safe enough?

The selection uses crypto.getRandomValues — the browser's cryptographically secure source — with rejection sampling so every word has exactly equal probability. Security comes from the math: with a list of 1,143 words, each slot contributes about 10.2 bits, so six words already top 61 bits. Nobody can exploit the list because no information about your choice leaves your device.

Is this the same thing as a passkey?

No, and it would be dishonest to blur the two. A passkey is a public-key credential stored on your device and registered with a website — nothing to memorize. A passphrase is a memorized secret. Passkeys are the better login mechanism where sites support them; a passphrase remains the right tool for master passwords and anywhere you still type secrets.

Is anything uploaded to a server?

No. The word list ships inside this page and generation runs entirely in your browser. Nothing is logged, and there is no history: reloading the page loses the passphrase on screen, which is exactly what you want after copying it.