Random word passphrases are stronger and easier to remember than complex passwords. Generate one below, instantly, in your browser.
Every passphrase is generated locally on your device and never transmitted anywhere. This tool runs entirely in your browser. You can disconnect from the internet after the page loads and it will keep working — proof that nothing is being transmitted. No accounts, no cookies, no analytics tracking what you type.
Security researchers have shown that a random passphrase of unrelated words — like the classic example "correct horse battery staple" — is typically harder to brute-force crack than a shorter password packed with symbols and substitutions, while also being far easier for a human to actually remember without writing it down.
This tool draws from a large word list to generate genuinely random combinations. Each additional word roughly multiplies the number of possible combinations, which is why 4-5 random words already produces a passphrase that would take an attacker an impractical amount of time to guess.
Words are selected using your browser's cryptographically secure random number generator (crypto.getRandomValues), not a weaker predictable random function. Combined with a large word list, this produces genuinely unpredictable combinations.
No — generate a unique passphrase for each important account. Reusing passwords means a breach on one site can compromise all your accounts. A password manager can help you store multiple unique passphrases securely.
Generally yes, up to a point — more words means more possible combinations. But check the specific site or service's maximum password length, as some systems cap it lower than you'd expect.
P@ssw0rd! feels strong and is cracked in milliseconds, because attackers’ dictionaries contain every such transformation. Four to six randomly chosen words produce far more entropy than a short “complex” password, while still being possible to memorise. Length and randomness are what defeat brute-force attacks — not symbol swaps.
A passphrase of six words from a 7,776-word list has about 77.5 bits of entropy — centuries of cracking time for even a well-funded attacker. An eight-character “complex” password tops out around 52 bits: hours to days. This is why modern guidance from NIST now prioritises length over forced symbol requirements.
A passphrase is a password made of several ordinary words picked at random, such as anchor-violet-kettle-summit. It looks less secure than a dense string of symbols, and it is dramatically more secure. The reason is arithmetic.
If words are drawn at random from a list of around 7,800, each word contributes roughly 13 bits of strength. Four words give about 51 bits; five give about 64; six give about 77. Crucially, that strength holds even if the attacker knows exactly which word list you used and exactly how many words you picked. There is no secret in the method, only in the dice rolls. That is the mark of a sound design.
Compare that with a human-chosen password. "Tr0ub4dor&3" looks like high-effort security and is worth about 28 bits in practice, because every transformation in it is one a cracking tool applies by default. The passphrase wins on strength and wins again on memorability, since human memory is built for words and images, not for punctuation.
The words come from your browser's cryptographic random number generator — the same source used for encryption keys — not from JavaScript's ordinary Math.random(), which is predictable enough to be unsuitable for anything security related. The word list avoids near-duplicates, very short words and words that are easily confused when spoken aloud, so the phrase stays strong and stays usable.
Nothing is generated on a server and nothing is recorded. Close the tab and the phrase is gone. If you want a phrase you intend to keep, generate it, commit it to memory or to your password manager immediately, and then move on.
The right number of words depends on what the passphrase protects.
Adding a digit or a symbol somewhere in the phrase is fine, mostly because some sites insist on it. Do not let it replace a word — one extra word is worth far more than one extra symbol.
The trick that works for nearly everyone is to build a short, absurd mental picture that links the words in order. For anchor-violet-kettle-summit, imagine a ship's anchor painted violet, wedged inside a kettle, sitting on a mountain summit. Ridiculous images stick; sensible ones do not. Recall the picture three or four times in the first hour, then again the next day, and it will be yours.
For the first week, write it down and keep it in your wallet — not taped to your monitor, not in a file called passwords.txt. The realistic risk is that you forget it and lock yourself out, not that a burglar takes your wallet for the sake of a login. Once you can recall it cold for several days running, destroy the paper.
Use a memorable passphrase for the handful of accounts you must be able to get into without help: your password manager, your primary email, your computer login, and your phone backup. For everything else, let a password manager generate long random strings you will never see and never need to remember. Memorising twenty passphrases is not realistic, and trying to do it leads straight back to reuse.
One warning worth repeating: never derive a passphrase from something published. Song lyrics, film quotes, scripture, book titles and famous speeches have all been fed into cracking dictionaries as complete phrases. The strength of this method comes entirely from the randomness of the selection.
Per character, no — a random character string packs more strength into less space. In practice, yes, because people can actually remember and correctly type a passphrase of 25 or 30 characters, while they cannot remember a random string of that length. Real security is what you use, not what looks best on paper.
Use as many words as fit, and prioritise turning on two-factor authentication for that account. A site with a short maximum length is often storing passwords in a way that is worth being cautious about, so make sure that password is unique to that site.
It is much weaker than it feels. People reach for the same few thousand common words and unconsciously pick ones that relate to each other or to themselves. Letting a generator pick is what makes the maths hold.
A little, and it satisfies sites that demand them. It is nowhere near as effective as adding one more word. Put them somewhere you will remember rather than sprinkling them through the phrase.
Yes. It is created on your device using your browser's cryptographic random generator, is never sent anywhere, and is not stored. Nobody, including us, can see or reproduce it.