Tools · Passphrase

Memorable passphrases, truly random.

Generate Diceware-style passphrases from the EFF short wordlist — easy to remember, hard to crack. Built with crypto.getRandomValues, all in your browser.

—

Generated locally with crypto.getRandomValues. No network, no logging, no telemetry.

Why passphrases work

Memorable · Random · Strong

Easy for you, hard for them

Humans remember words far better than random characters. A handful of random words is easy to recall and type, yet still uniformly random where it counts — in the choice of each word.

Entropy from the wordlist

Each word contributes ~10.2 bits. Six words is ~61 bits before you even add a number or capital. Verify any result with the entropy calculator.

Perfect for master passwords

A long passphrase is the ideal master password for a vault like Apex — one strong secret you can actually remember, guarding everything else.

Passphrase Generator FAQ

Common questions

What is a passphrase?

A passphrase is a sequence of random words, like “correct-horse-battery-staple”. Because the unit of randomness is the whole word, passphrases are easy to remember and type while providing entropy equal to or greater than a random character string.

What is Diceware?

Diceware is a method of building passphrases by selecting random words from a numbered wordlist using dice. This tool does the same thing with a cryptographically secure random number generator instead of physical dice, drawing from an EFF-based short wordlist (1,193 words).

How many words do I need?

Each word from the wordlist adds about 10.2 bits of entropy. Four words (~41 bits) is fine for low-value accounts; six words (~61 bits) is strong; eight or more (~82 bits) is excellent for a master password.

Is a passphrase as secure as a random password?

Yes, for equal entropy. A 6-word passphrase (~61 bits) is comparable to a ~10-character fully random password, but far easier to remember. For the strongest accounts, use 8+ words or combine with a generated random password.

Ready for the full vault?

Stop reusing. Start sealing.

Apex Password stores every credential end-to-end encrypted, on your device. The relay never sees plaintext.