Passphrase generator

Random words from the EFF wordlist — easy to type, hard to guess, generated in your browser

Generated in your browser. This page is not allowed to make network requests, so nothing you generate can leave it.

Why a passphrase

A passphrase is several words picked at random — not a sentence you thought of. Its strength comes from the randomness of the choice, not from tricks like swapping letters for digits, so it can be as strong as a random password while staying easy to type on a phone, remember, or read out over a call. That makes it the right choice for the few secrets you have to carry in your head: a password-manager master password, a laptop or disk-encryption password, a Wi-Fi password guests type by hand.

How strong is it?

Words are drawn independently and uniformly — classic diceware — from the EFF Short Wordlist #2, 1,296 words. Each word adds log2(1,296) ≈ 10.3 bits.

WordsEntropyGood for
4~41 bitsLow-value accounts behind rate limits
5~52 bitsOnline accounts
6~62 bitsOnline accounts, comfortably
7~72 bitsMaster passwords, device encryption
8~83 bitsAnything that could be attacked offline
10~103 bitsLong-term secrets

The calculation assumes the attacker knows the wordlist and exactly how the phrase was made. That is the point: the security does not depend on keeping the method secret. It does depend on not editing the result — replacing a word with one you like, or rerolling until you get a phrase you find pleasant, makes it less random. Regenerate freely; just don't hand-pick.

Why this wordlist

The EFF published its lists to replace the original diceware list, which had obscure words and odd strings. The short list #2 used here has words with unique three-letter prefixes and at least three edits apart from each other, so typos are rarely ambiguous and a phrase survives being spoken aloud. It is the same list OncePad draws its seven-word sharing passphrases from. The EFF's large list (7,776 words, ~12.9 bits per word) needs fewer words for the same strength but uses longer ones.

Capitals, separators, and numbers

These exist to satisfy sites with composition rules ("must contain a capital and a number"). Capitalizing every word adds nothing an attacker has to guess; one random digit in one random word adds about 6 bits. If you want a stronger phrase, add a word.

Frequently asked questions

How many words should a passphrase have?

With this 1,296-word list each word adds about 10.3 bits. Six words (~62 bits) is reasonable for an online account; use seven or more (~72+ bits) for anything an attacker could attack offline, such as a password-manager master password or disk encryption.

Is a passphrase better than a password?

Not stronger per character, but far easier to type, remember, and read aloud. A seven-word passphrase and a 12-character random password have similar strength; most people can remember the first.

Which wordlist does this use, and does it matter that attackers know it?

The EFF Short Wordlist #2 — 1,296 words with unique three-letter prefixes, chosen to be easy to type and hard to confuse. Attackers knowing the list is assumed: the strength comes entirely from the random choice of words, which is why you should not swap in words of your own.

Do capitals, separators, or a number make it stronger?

Barely. Capitalizing every word adds nothing, and one random digit adds about 6 bits. They exist to satisfy sites with composition rules; adding a word is the real way to add strength.

Is anything sent to OncePad?

No. The words are picked in your browser and the page is not allowed to make network requests. Sharing it as a one-time link encrypts it in your browser before anything is uploaded.