Passphrase generator
A passphrase is a password made of random words. Choose the number of words; your browser draws them from a published list of 7,776 words and shows how strong the result is.
This tool needs JavaScript. The rest of the page works without it.
Your result will appear here.
The list of 7,776 words is loaded from this site once.
Dice numbers of the words
Each word stands for one throw of five dice in the EFF list. You can look the numbers up in the published list to check the words.
Something went wrong. Your entries are still here.
How to use it
- Set the number of words. 6 is preset; use more for a password that protects other passwords, such as the main password of a password manager.
- Choose what goes between the words. A hyphen or a period works on most sites; some sites do not accept spaces.
- Tick “Capitalize each word” or “Add a random digit” only if the site demands capitals or a number.
- Select “Generate passphrase”, then “Copy result”, and paste it into the site and into your password manager.
How the passphrase is made
The tool uses the EFF Large Wordlist: 7,776 different English words of 3 to 9 characters; four of them contain a hyphen, such as t-shirt. For every word of the passphrase it draws one number from 0 to 7,775 with the cryptographic random generator of your browser, discarding values that would favour some words, and takes the word at that place. Every word is drawn on its own, so a word can occur twice, as it can when you throw dice.
Strength is measured in bits of entropy: the base-2 logarithm of the number of equally likely passphrases. One word has log2(7,776) = 12.925 bits, because 7,776 = 2^12.925. Words multiply the possibilities, so their bits add up: six words have 6 × 12.925 = 77.5 bits.
The random digit is one of 10 digits after one of the words, so it multiplies the possibilities by 10 times the number of words: log2(60) = 5.9 bits with six words. Capital letters add nothing: every word gets one, so an attacker who knows the method knows that too. The calculation assumes the worst case, an attacker who knows the list, the number of words and every option you chose.
Worked example
In the EFF list, the dice throws 16161, 24242, 33333, 43434, 52525 and 61616 stand for the words below. Drawn by the tool, the same six words would give this passphrase:
| Dice | Word |
|---|---|
| 16161 | clock |
| 24242 | driven |
| 33333 | handgrip |
| 43434 | palpable |
| 52525 | sacrament |
| 61616 | talisman |
With hyphens the passphrase is clock-driven-handgrip-palpable-sacrament-talisman, 77.5 bits. With capitals and a digit it could be Clock-Driven-Handgrip7-Palpable-Sacrament-Talisman: 77.5 + 5.9 = 83.5 bits. Do not use this example; it is published here.
| Words | Bits | With a random digit |
|---|---|---|
| 4 | 51.7 | 57.0 |
| 5 | 64.6 | 70.3 |
| 6 | 77.5 | 83.5 |
| 7 | 90.5 | 96.6 |
| 8 | 103.4 | 109.7 |
| 10 | 129.2 | 135.9 |
Each bit doubles the number of guesses. Whether a number of bits is enough depends on how a service stores passwords and limits attempts, which you usually cannot see, so more words are the safer choice.
Common mistakes
- Replacing words with ones you like. A person picks predictable words, and the calculation no longer holds. Picking the best of ten generated passphrases costs at most log2(10) = 3.3 bits; choosing words yourself can cost far more.
- Using the same passphrase on several sites. If one site leaks it, all of them are open. Use a password manager for the rest.
- Adding a digit or a symbol at the end by hand. Attackers try that first; it adds little.
- Keeping the passphrase in a note or a chat. Store it in a password manager or write it down and keep the paper safe.
Word list and licence
The EFF Large Wordlist for Passphrases was made by the Electronic Frontier Foundation (EFF) and is published under the Creative Commons Attribution 3.0 United States licence (CC BY 3.0 US). This site uses the list without changes. The EFF has no connection with this site and does not endorse it.
The method of choosing words with dice is known as Diceware and was described by Arnold Reinhold in 1995. The EFF list was made for it: five throws of a die select one word.
Frequently asked questions
- Is a passphrase better than a random password?
- It is easier to type and to remember at the same strength, but it is longer. Six words have 77.5 bits; a random password of 16 characters from letters, digits and symbols has about 99. Where you only paste from a password manager, a random password is shorter; where you type or remember it, a passphrase is easier.
- Is the passphrase sent anywhere or stored?
- No. The word list is loaded from this site, and the words are drawn by your browser. The passphrase is not sent, not stored and gone when you leave the page. This page shows no advertising.
- Why can the same word appear twice?
- Because each word is drawn independently, as with real dice. The calculation of the strength includes these repeats. Leaving repeats out would make the passphrase very slightly weaker, not stronger.
- Can I use real dice instead?
- Yes. Throw five dice for each word, read them in order, such as 1-6-1-6-1, and look the number up in the EFF list: 16161 is clock. The tool shows the dice numbers of its words, so you can check them in the published list.
- Can I make a Wi-Fi password with it?
- Yes. A WPA or WPA2 password has 8 to 63 characters, so choose a number of words that stays within 63 characters. Then make a Wi-Fi QR code so that guests do not have to type it.
Last updated: September 29, 2026