zavashop

Passphrase Generator

A passphrase made of several truly random words is easier to remember and type than a jumble of symbols, and just as hard to guess. This generator picks words with your browser’s cryptographic random number generator — nothing is sent anywhere — and shows exactly how strong each passphrase is.

Passphrase generator

Offline: roll four dice

Passphrase and Account Security Pack

Printable 1,296-word dice list for offline passphrases, a password manager setup worksheet, an account security checklist, an account inventory sheet (no passwords) and a digital-legacy planning sheet.

Formats: PDF, DOCX, XLSX. Instant download after payment (link valid 72 hours, up to 5 downloads). AI-assisted: the templates were drafted with AI help and reviewed and laid out by Kedop.

$5.00 USD, one-time

Secure card checkout by Stripe. Full refund within 7 days — see the refund policy and license.

How strong is a passphrase?

WordsEntropy (4,096-word list)Entropy (1,296-word dice list)Typical use
448 bits41 bitsLow-value accounts only
560 bits52 bitsEveryday accounts
672 bits62 bitsEmail, banking (with 2FA)
784 bits72 bitsPassword manager master password
896 bits83 bitsDisk encryption, long-term secrets

Each word chosen at random from 4,096 adds exactly 12 bits: every extra word makes the passphrase 4,096 times harder to guess. Length of the words themselves doesn’t matter — only how many random choices were made.

Why random words beat clever passwords

Human-chosen passwords follow patterns — capital first letter, a word, a year, an exclamation mark — and password-cracking tools try those patterns first. A passphrase like “Summer2024!” is weak however long it looks. Randomly chosen words have no pattern to exploit: the only way to find one is to try combinations from the word list, and six words from 4,096 gives about 4.7 × 10²¹ possibilities. Just as important, a string of words is easy to remember and to type on a phone.

Worked example

With the default settings — six words, hyphens, no capitals — each passphrase has 72 bits of entropy. At 100 billion guesses per second, the kind of speed a well-equipped attacker might reach against a fast, poorly protected password hash, finding it would take on average about 750 years. Against a site that uses a slow, modern hash such as bcrypt or Argon2, the attack is millions of times slower still. Adding a random digit adds a few more bits (5.9 bits for 6 words), which helps with sites that insist on a number.

Rolling dice for an offline passphrase

  1. Take four ordinary six-sided dice (or roll one die four times).
  2. Read them in order, for example 3-1-4-1, to get a four-digit code.
  3. Look the code up in the printable dice word list from the pack, or type it above.
  4. Repeat for each word you need — six or seven words is a good target.
  5. Write the passphrase down until you have memorised it, then store the note safely or destroy it.

Dice are a trustworthy source of randomness you can see with your own eyes — useful for a master password you never want to generate on a computer.

Password managers and the one passphrase to remember

The safest everyday setup is a password manager that creates and stores a long random password for every site, protected by one strong passphrase you memorise. That master passphrase is the one place where a seven- or eight-word passphrase really matters: if someone got a copy of your encrypted vault, it is the only thing standing between them and every account. Practise typing the new passphrase several times a day for the first week, and keep a written copy in a safe place until it sticks.

Sites with password rules

Some sites still demand an uppercase letter, a number and a symbol, or cap the length. The options here cover most of those rules: capitalise the first letter of each word, add a random digit, and use a hyphen or dot as the separator. If a site limits passwords to something short like 16 characters, use a four-word passphrase without separators only as a last resort — or better, let your password manager generate a random string for that site.

Using passphrases well

About the word list

The generator uses 4,096 common English words of four to eight letters, compiled from everyday vocabulary on Kedop pages, with plurals of other listed words and potentially upsetting words removed. The dice list is the 1,296 most common of those words. Words are chosen with crypto.getRandomValues — the browser’s cryptographically secure random number generator — using rejection sampling so every word is equally likely.

What’s in the template pack

The generator is free; the pack is a one-time download.

Privacy

Passphrases are generated in your browser and never sent to our server or anyone else. Nothing is stored.

Frequently asked questions

How many words should a passphrase have?

Six or more for important accounts; seven or eight for a password manager or encryption.

Is a passphrase better than a password?

A random passphrase is as strong as a random password of similar entropy and much easier to remember and type.

Are these passphrases really random?

Yes — they use your browser’s cryptographic random generator.

Do spaces or capitals make it stronger?

Only slightly; strength comes mainly from the number of random words.

What is entropy?

A measure of unpredictability in bits; each extra bit doubles the number of guesses needed.

Can I use dice instead of a computer?

Yes — roll four dice per word and look up the code in the dice list.

Should I use a passphrase from this page?

Generate your own and don’t reuse any example you see written down.

Is anything sent to your server?

No, everything happens on your device.