My PassphraseNothing leaves this page.
Offline: works with the wi-fi
off.
One file: nothing to install.
A free passphrase & password generator. Truly random, made entirely in your browser. Nothing is stored or sent.
How to run mypassphrase.app safely, in 6 steps
Getting a password from a website? Really? Fair question. This page never touches the internet (no images, no fonts, no scripts) and it tells your browser to refuse if it ever tried. Check the Network tab in your browser's developer tools to verify.
Browser extensions are the risk this page cannot touch. Anything you have added to your browser can read what appears on this page. For a passphrase that will guard something important, use a browser profile with nothing installed in it.
- Get the file while you are still online. Download the latest release: one file, nothing to install, and the only copy whose SHA-256 matches the checksum published beside it. The README shows how to check it.
- Make a fresh browser profile. Chrome/Edge: profile icon → Add; Firefox:
about:profiles→ Create a New Profile. Install nothing into it, sign in to nothing. - Turn off Wi-Fi and unplug any internet cable.
- Open the downloaded file in that profile and check the badge below reads Offline: safe to generate.
- Generate your passphrase, then write it down, memorize it or store it in your password manager.
- Close the browser completely before reconnecting.
And for the truly paranoid, take the randomness away from the computer entirely: roll dice. The EFF wordlist holds exactly 7,776 words, every outcome of five six-sided dice, so five rolls pick one word, repeated until your passphrase is long enough. Look each roll up in the EFF's published list, or a printout of it if even the lookup should happen off-screen. Physical dice are randomness nobody has to audit.
Math.random. Edit the box to test
a password of your own; nothing is saved, recorded or sent anywhere.
Makes it stronger. Each press capitalises one random letter and adds a random
digit or symbol at the edge of a word, taking turns, so two
presses cover the capital, digit and symbol that many sites ask for. The same
random generator makes every choice, so the bits added are
counted, not estimated, and priced as if an attacker knows this
button exists. The button shows what the next press is worth.
Encode
The same secret in another alphabet
A costume, not a lock: encoding adds zero bits.Anyone who knows the alphabet reads it straight back, so the string deserves the same care as the phrase itself. It is for the sites and devices that demand hex or Base64. Don't test it in the box above: the meter cannot see the words inside the hex, and would overrate it.
Decode
A string back to its text
Decoding needs no key: a string is hidden only as well as its hiding place.Anyone who finds the string and guesses the alphabet reads it just as easily. It all happens in this page and nothing is sent. To judge the secret, test the decoded text, not the string.
Q & A
Why should I use a random passphrase?
Because humans are terrible at creating secure passwords. We base them on things we can remember (names, dates, common words), then add some spice with a capital letter, a number or a symbol. Crackers know every one of those patterns, and passwords built from them fall instantly.
| Pattern | Example | Time to crack |
|---|---|---|
| A common word | december | less than a second |
| A keyboard pattern | qwerty | less than a second |
| The family dog | rusty | less than a second |
| A date or zip code | 03261981 | less than a second |
| Letter→number swaps | S4nfr4n | less than a second |
| Four random words | candle harvest anchor velvet | 30 minutes |
The last row is what the generator draws: four words, 52 bits. Type those same four words in yourself and the meter shows less, because it cannot tell whether you rolled for them or picked them; see “Why do the same words score differently when I type them in?” below.
Those times assume what the meter assumes: a website that had your password got hacked, scrambled its stored passwords carelessly, and the thieves are guessing a trillion times a second. Every recognisable pattern falls before the first tick of the clock; random words are the only row still standing.
But the clock is the lesser number here. What actually separates the last row from the rest is randomness, and that is what the meter measures: each random word multiplies a guesser's work about 8,000-fold, which is 13 bits. Four words carry about 52 bits; six carry 78, which reaches the 💪 mark on the meter and passes beyond the reach of any offline grinding. The time underneath is only that bit count run through an assumption about someone else's hardware.
Words or ASCII characters: which should I use?
Both are offered here, and generated at random they are both strong; the difference
is what your memory has to carry. (The counts below are what the generator draws;
typed in by hand they read lower, for the reason given further down.) ipz2!az8k%0h and
finite anchor velvet harvest candle ruby hold almost exactly the same
randomness (79 bits against 78) and both take centuries to crack, but only one of
them survives being typed from memory. Use words for anything you
personally have to remember and type: a master password, a computer login. Use
ASCII characters where a password manager fills the field for you, or where a
site's length limit squeezes out a passphrase.
How are passwords actually cracked?
Roughly in this order: first wordlists (the top 10,000 passwords crack about 30% of
accounts in under a second), then the same lists with common substitutions
(december → D3cember), then combinations like name + date, and
finally brute force over every character. Depending on how a site protects its password
database, modern hardware makes anywhere from about 10,000 guesses per second to a
trillion or more.
A password built from any recognisable pattern eventually falls to this; a passphrase
chosen truly at random has no pattern to exploit.
Can I use this for a wallet (BIP-39) passphrase?
Yes, and it is what this generator suits best, but the rules are different from a website password, in two directions at once.
It has to be stronger. There is no server to throttle anyone. A thief who finds your seed backup guesses offline, at full speed, for as long as they like, so the pessimistic rate on this page is the only rate that applies. Six words clears that; seven is the sensible choice when the wallet holds real money.
And it has to be reproducible forever. A wallet passphrase has no reset: one wrong character opens a different, empty wallet, with nothing to tell you it was the wrong one. Write it on metal, store it apart from the seed itself, and restore the whole thing onto a wiped device before you fund it. Far more coins are lost to a passphrase nobody can reproduce than to one somebody guessed.
Generate it with this page offline (see the six steps at the top) or with physical dice against the EFF list. The moment you pick the words yourself, none of the arithmetic on this page describes what you have.
How are the bits and the crack time worked out?
Two different ways, depending on where the secret came from, and the difference matters more than anything else on this page.
For anything this page generated, the count is exact and nothing is estimated. Six words drawn from a list of 7,776 is 7,776⁶ possible phrases, which is 77.55 bits, shown as 78. It is the same 78 for every six-word draw, however ordinary or exotic the words look, because a guesser has to search the whole list either way. That figure is arithmetic, not a judgement.
For text you type, the page has no idea where it came from: dice, a
password manager, or the first line of a song. So it can only estimate, and it marks
the number est. The estimate comes from zxcvbn, an open-source
strength estimator created at Dropbox, and
don't let the name on the box put you off: it has become the industry's de-facto
standard, the same engine behind the strength meters in major password managers
(Bitwarden among them) and at login providers such as Stripe and GitLab. Rather than
just counting characters, it hunts for the patterns real crackers try first
(dictionary words, names, dates, keyboard runs, letter-for-number swaps) and estimates
how many guesses your text would survive. It is a good estimator, but an estimator
is all it is: it prices each word by how common the word is in English, which is a
different question from how large a list the word was drawn from.
Because that error runs in the flattering direction, one limit is put on top of it. A word that appears on one of the lists above cannot be worth more than the list it came from: anyone who knows the recipe simply tries all 7,776, so that is a ceiling, not a courtesy. Words on no list keep the estimator's own figure, since nothing can be proved about them. It only ever lowers a number, and never credits one: a phrase whose words you chose yourself is still capped rather than counted, and its real worth is lower again, because people do not choose uniformly.
Either way, the page turns the bit count into a time at a trillion tries a second: the rate a serious rig manages against passwords a hacked website stored carelessly. It is deliberately the pessimistic end, because you never get to choose how well a website guards what you gave it. Treat the figure as a comparison tool, not a promise: the bits above it are the number that is actually measured, and the time is only that number run through an assumption about somebody else's hardware.
What does est. mean next to the number?
Estimated, nothing more. It appears whenever the box holds something the page
did not draw itself, which includes a generated passphrase you have since edited by
so much as one character. It is not a verdict on your words: a brilliant passphrase
and password123 both get it.
Read it as a confidence label. A number without est. is arithmetic the page can prove. A number with it is a guess about text whose origin the page cannot see, and a guess that can land either side of the truth.
Why do the same words score differently when I type them in?
Because the page is answering two different questions.
When it draws the words, it knows the recipe: six independent picks from 7,776 words is 78 bits, every time, whichever words come out. When you type them, it has no way to know whether you rolled dice or chose your favourites, so it falls back to the estimator, which prices each word by how common the word is in English. Rare words get priced high, everyday ones low, and the total wanders either side of the truth. Type in six words the button gave you a moment ago and you can watch the figure change, though not one word did.
Which is right? If a random process chose the words, the generated figure is: an attacker who knows you used the EFF list faces all 7,776⁶ phrases no matter how exotic yours look. And if you picked the words yourself, the honest number is lower than either, because people do not choose uniformly: we avoid repeats, reach for words we find interesting, and skip the ones that feel odd. That is the one direction this meter must never flatter, which is why typed words are never credited at the list's rate.
It says my passphrase “reads like a sentence”. What does that mean?
That the estimator is about to overrate it badly, and the page would rather warn you than hand you a comforting number.
The estimator prices each word on its own and has no model of grammar, so it cannot see that your is usually followed by own rather than by urologist. A sentence therefore scores like a passphrase while being nothing of the kind. The label above this very field, typed into it, once read 86 bits and twelve thousand centuries, for a line of text printed on the page and published in a public code repository.
The warning fires on function words (the, of, to, it, and) because a sentence is built from them and words drawn from a list contain almost none. The number itself is left alone: the true strength of a sentence is not something this page can work out, and quietly substituting a smaller invented figure would be no more honest than the large one. If you want a number that can be counted, press Generate.
What do the 💪 and 🌱 marks on the meter mean?
💪 at 78 bits is the line that matters: six words, the point past which offline guessing stops being a threat at any plausible speed. Everything from there rightward is green.
🌱 at 128 bits is a comparison, not a target. It is the randomness in a 12-word seed phrase, put there so you can see how a passphrase measures against the thing it often sits beside. Reaching it is not a requirement, and the meter does not treat anything short of it as lacking: a six-word passphrase is already past every attack the number describes.
What is the difference between the two wordlists?
The EFF large wordlist is 7,776 words chosen by the Electronic Frontier Foundation specifically for passphrases: every word is common enough to spell, no word is a prefix of another, and easily-confused pairs were removed. Its 7,776 entries match the outcomes of five dice rolls, so the same list works offline with physical dice. Common English is 7,459 everyday words drawn from the most frequently used words in English, so the phrases read a little more naturally, at the cost of the EFF list's careful curation. Both lists give about 13 bits of randomness per word, so the strength is essentially the same; pick whichever produces phrases you find easier to remember.
Where does the randomness come from?
From crypto.getRandomValues, the random number generator your browser
provides for security work. The everyday one, Math.random, is predictable
enough that it should never choose a password, and it appears nowhere in this file.
None of the four pools is a round number in binary, so each draw uses rejection
sampling (a draw that lands past the end of the pool is thrown away and taken again)
which keeps every word, and every character, exactly as likely as every other. No
modulo, so no modulo bias.
What exactly is in the ASCII pool?
Every printable ASCII character except the space, 94 in all: letters in both cases,
the digits, and every symbol on a US keyboard. That is the classic
ipz2!az8k%0h-style random password. Each character carries about 6.6 bits,
and the pool is drawn from with the same cryptographic generator and the same rejection
sampling as the wordlists, so every symbol is exactly as likely as every other. Some
sites reject certain symbols; if one does, just generate again, and never trim or swap
characters by hand.
What is the PIN pool, and why is its crack time so scary?
Random digits for device PINs, the kind a hardware wallet asks you to set. Each
digit is drawn independently, so leading zeros are as likely as anything else:
0042 is a perfectly good 4-digit PIN, which is exactly what
pick-a-number-in-a-range generators can never give you. A digit carries about 3.3 bits,
so a 6-digit PIN is only ~20 bits and barely registers on the meter.
That figure is honest, but it describes an attacker who can guess without limit. A
PIN's real protection is the device's lockout: hardware wallets throttle,
lock or wipe themselves after a few wrong tries, so ~20 bits is fine there. The same
20 bits is catastrophic anywhere unlimited guessing is possible. Never reuse a device
PIN as an online password.
How many words, or characters, do I need?
Each word adds about 13 bits, and every bit doubles the work a guesser faces. The line that matters is 78 bits (six words), the 💪 mark on the meter. Below it, how much is enough depends on who is guessing; above it, nobody is.
| Length | Bits | Good for |
|---|---|---|
| 4 words | 52 | A site that locks after wrong tries, not a stolen password file |
| 5 words | 65 | The same, with more room to spare |
| 6 words | 78 | Past offline guessing. A good master password. |
| 7 words | 90 | Wallet passphrase, or anything guarding real money |
| 10 words | 129 | Matches a 12-word seed, 🌱 on the meter |
Four words is fine for a login that throttles guesses, and falls in half an hour to a rig grinding a stolen password file, which is why the meter names the case rather than calling it good or bad. Six words ends that argument. Seven is the one to reach for when the secret guards money, not because six is breakable but because it costs you a single extra word.
Going far past that is not free either. Ten words buys nothing a guesser will ever notice, while adding three more words to write down, to check, and to get wrong on a metal backup. And losing a passphrase you cannot reproduce is far more likely than anyone guessing one.
In ASCII mode the same arithmetic runs per character: each of the 94 symbols carries about 6.6 bits, so 8 characters matches a 4-word phrase, 12 characters (79 bits) matches six words, and 16 characters (105 bits) beats an 8-word one.
What else should I do beyond a good passphrase?
Three things: use a password manager, so each site gets its own password; use a strong master passphrase for that manager, which is exactly what a generated passphrase is for; and never reuse a passphrase between sites, because a breach at one becomes a breach at all of them.
Does anything I type here leave my computer?
No. The page never sends anything anywhere, and it tells your browser to block the attempt if it ever tried. Nothing at all is fetched from the internet, not a typeface, not an image, not a line of code. Nothing is saved or logged either. That covers this page only, though: a browser extension can read what you type here, and no web page can stop it.