Skip to content

Passphrase Generator

Generate a passphrase from a curated 256-word list using the same Web Crypto randomness as this site's Password Generator, not Math.random. The word list is exactly 256 entries on purpose — each word is exactly 8 bits of entropy, so the total entropy is honest and easy to state, not a rough guess.

  • Cryptographically random, not Math.random
  • 256-word list — exactly 8 bits of entropy per word
  • Optional capitalization, custom separator, trailing number
  • Shows the real entropy in bits, not a strength label
  • Runs fully client-side

Generator

Generated locally with Web Crypto, nothing uploaded

Passphrase

How to generate a passphrase

  1. 01

    Set the word count

    More words means more entropy — 5 or 6 is a reasonable default.

  2. 02

    Pick a separator and options

    Hyphen, underscore, dot or space; capitalize words; add a trailing number.

  3. 03

    Generate

    The real entropy in bits is shown alongside the result.

Why the word list is exactly 256 words#

256 is 2^8: with a list of exactly that size, every word contributes exactly 8 bits of entropy, no rounding involved. A 5-word passphrase is exactly 40 bits from the words alone, a 6-word one exactly 48 — round, honest numbers instead of an approximate "log2 of some list size" that most passphrase tools quote without showing their actual list.

Why this uses Web Crypto, not Math.random#

Math.random is a fast, predictable pseudorandom generator — fine for a UI animation, not for anything where genuine unpredictability matters. This tool uses crypto.getRandomValues with rejection sampling, the same source this site's Password Generator and Dice Roller use, so every word in the list is exactly equally likely to be picked.

Frequently asked questions

How much entropy does a passphrase actually have?

Exactly 8 bits per word (the list has exactly 256 entries), plus about 6.6 bits if the optional 2-digit number is included. A 5-word passphrase with the number is about 46.6 bits total — shown live under the result.

Why not use Math.random like most passphrase generators?

Math.random is a predictable pseudorandom generator. This tool uses crypto.getRandomValues instead, the operating system's cryptographically secure random source, with rejection sampling so every word is exactly equally likely.

Is a passphrase safer than a random-character password?

For the same entropy, they are equally strong against a brute-force attack — a passphrase is just easier for a human to remember and type. Entropy is what matters, not word count versus character count.

Is my passphrase sent anywhere?

No. It is generated entirely in your browser.

Developers

UUID Generator

Generate cryptographically random UUID v4 or time-ordered UUID v7, in bulk.

Developers

Base64 Encoder & Decoder

Encode and decode Base64 with correct UTF-8 handling, including the URL-safe alphabet.

Developers

ULID Generator

Generate ULIDs — sortable by creation time like UUID v7, but Crockford Base32 instead of hex.