Secure Passphrase Generator
Generate a strong, random and memorable passphrase locally in your browser.
Your passphrase
Generated locally in your browser. Nothing is sent to PassCheckup.
How does this work?
PassCheckup generates your passphrase with code running directly in your browser, using your browser’s built-in cryptographic random number generator.
Generated passphrases aren’t sent to PassCheckup’s servers or stored in cookies, browser storage or analytics. Copy places the passphrase on your device’s clipboard only.
Refreshing or closing the page discards the current passphrase.
Adjust
About this passphrase
Why this is strong
The words were selected independently using cryptographically secure randomness. The strength comes from the number of possible random combinations, not from making the passphrase look complicated.
This applies to randomly generated passphrases. A phrase you make up yourself is far more predictable, even with the same number of words.
The added digit helps with sites that require a number. It isn’t counted in the generated entropy.
Want more guessing resistance?
Add another randomly selected word. Each additional random word substantially increases the number of possible passphrases.
Already have a password? Check its strength with the Password Strength Checker.
What is a passphrase?
A passphrase is a password made of several words, such as harbor-lantern-cactus-orbit-magnet-silver. This generator doesn’t ask you to invent a memorable sentence. It picks each word at random, which is what makes the result hard to guess while staying easier to remember and type than a string of random characters.
What makes a random passphrase strong?
Its strength comes from the number of possible combinations. Each word is chosen independently from a list of7,776 words, so every position could be any of 7,776 words. Six positions give 7,776 multiplied by itself six times: about 2.2 × 1023 possible passphrases.
That only holds when the words are truly random. Capital letters, separators and symbols don’t add much on their own; the random selection is what matters.
How many words should I use?
Every additional randomly selected word multiplies the number of possible passphrases by 7,776. This generator defaults to 6 words (about 78 bits of generated entropy) and lets you choose from 3 to 8. Fewer words are easier to type, more words give more guessing resistance. For passwords that protect many others, such as a password manager’s master password, more words are a reasonable choice. No word count guarantees an account’s security on its own.
Passphrase vs. password
A random passphrase and a random password can be equally hard to guess. The difference is practical: words are easier to remember and type correctly, so a long random passphrase is often more usable than a random string of the same strength.
A passphrase is not automatically stronger. A quotation, song lyric or sentence you make up is much easier to guess than its length suggests, because guessing tools try common phrases. The strength of a generated passphrase comes from random selection, not from being made of words.
How this generator works
- Randomness comes from your browser’s built-in cryptographic random number generator (
crypto.getRandomValues). - Each word is selected independently and uniformly from the 7,776-wordEFF Long Wordlist. Random values that would make some words slightly more likely than others are discarded and redrawn, so every word is equally likely.
- Everything happens locally in this page. There is no server-side generation.
- Generated entropy is the number of words multiplied by log₂(7,776), about 12.9 bits per word. Capitalization, the separator and the optional number are not counted.
Privacy
Passphrases are generated in your browser and exist only in the page’s memory. They are not sent to PassCheckup, stored in cookies or browser storage, or included in the page address. Refreshing or closing the page discards the current passphrase. Copying places it on your device’s clipboard.
Frequently asked questions
Is this passphrase generator secure?
It uses your browser’s cryptographic randomness, selects every word with equal probability, and runs entirely on your device. That makes the generated passphrase hard to guess. Your account’s security also depends on things a generator can’t control, such as reusing passwords, phishing, malware and how each website stores passwords.
What makes a passphrase strong?
Random selection from a large word list and enough words. The number of possible combinations, not visual complexity, determines how hard it is to guess.
How many words should a passphrase have?
PassCheckup defaults to 6 randomly selected words. Each additional word multiplies the number of possibilities by 7,776, so more words give more guessing resistance. Choose a length that fits how the password will be used.
Are passphrases better than passwords?
Not automatically. A randomly generated passphrase is hard to guess and easier to remember than random characters. A made-up sentence or well-known phrase can be much weaker than it looks.
Can PassCheckup see my generated passphrase?
No. The passphrase is generated in your browser and is not sent to PassCheckup or stored by it.
What does generated entropy mean?
It measures how many passphrases the generator could have produced, in bits: each bit doubles the number of possibilities. Because PassCheckup knows exactly how the words were chosen, it can calculate this directly. For example, 4 random words give about 52 bits and 6 give about 78 bits. The figure applies only to randomly generated passphrases, not to phrases people choose themselves.
Is this a Diceware generator?
It uses the EFF Long Wordlist, which was designed for Diceware-style generation with five dice rolls per word. PassCheckup doesn’t roll physical dice. It selects each word with your browser’s cryptographic randomness, giving every word the same chance, as fair dice would.