Generate strong, memorable diceware-style passphrases to protect SSH private keys. Word count, separators and an entropy estimate, generated locally in your browser.
Use this free online SSH Passphrase Generator directly in your browser. No signup required, no data leaves your device. Part of Utilier — a collection of 139+ developer utilities.
What is SSH Passphrase Generator (Diceware-style, Memorable)?
An SSH passphrase is the secret that encrypts your private key on disk, so that a stolen key file cannot be used without it. This tool generates strong, memorable passphrases in the diceware style: several ordinary words chosen at random from a word list using the Web Crypto secure random generator, joined by a separator, with optional capitalization and an appended digit or symbol. It estimates the entropy so you can see how strong each passphrase actually is.
Memorable by construction: A handful of short, common words is far easier to remember and type than an equivalent-strength jumble of random characters, which matters because an SSH passphrase is typed often. Diceware trades a little length for a lot of memorability at the same entropy.
Entropy you can see: Each word contributes log2(list size) bits, and adding a digit or symbol adds a little more. The status line reports the estimated bits so you can choose a comfortable strength rather than guessing whether four words is enough.
Configurable shape: Choose the number of words, the separator (dash, dot, underscore, space or none), whether words are capitalized, and whether to append a random digit and symbol — enough to satisfy most passphrase policies while staying typable.
Generated locally: Words are drawn with crypto.getRandomValues entirely in the page. Nothing is sent to a server, so a passphrase you generate here is never transmitted before you use it with ssh-keygen.
Why use the SSH Passphrase Generator?
An unencrypted SSH private key is a plaintext credential: whoever copies the file gets your access. A passphrase turns key theft from an instant compromise into a hard offline attack — but only if the passphrase itself is strong, which is exactly where hand-chosen phrases fail.
Protect the key at rest: If a laptop is lost, a backup leaks, or a repo accidentally commits a key, a strong passphrase means the attacker still has to break the encryption before they can authenticate anywhere with it.
Strong without being unmemorable: People defeat character-soup passphrases by writing them down or reusing them. A five- or six-word phrase reaches 60–75+ bits while remaining something you can actually recall and type at a prompt.
Predictable strength: Because entropy is words × log2(list size), you can pick a word count to hit a target strength deliberately, instead of hoping a clever phrase is strong. The estimate is shown so the choice is informed.
Good default for key rotation: When you generate a new key pair or rotate a compromised one, you need a fresh passphrase immediately. A generator gives you one with known strength on the spot.
When to use the SSH Passphrase Generator
Use it whenever you create or re-encrypt an SSH key, or anywhere a memorable-but-strong secret is preferable to a random character string.
Creating a new SSH key pair with ssh-keygen and being prompted for a passphrase.
Adding or changing the passphrase on an existing key with ssh-keygen -p.
Rotating a key that may have been exposed and needing a fresh strong passphrase quickly.
Protecting other private keys or keystores (GPG, PKCS#12, disk images) that take a human-entered passphrase.
Choosing a master password for a password manager or full-disk encryption, where memorability matters.
Teaching why a multi-word passphrase can beat a short random password on both strength and usability.
How to use the SSH Passphrase Generator
Set the shape, generate, and use the passphrase with ssh-keygen — all locally.
Choose the word count: More words means more entropy. Four words is a reasonable floor; five or six is a strong, still-memorable default. The estimate updates when you generate.
Pick a separator and options: Select dash, dot, underscore, space or none. Optionally capitalize each word and append a random digit and symbol to satisfy policies that demand them.
Generate: Click Generate to produce one or several unique passphrases. The status line shows the approximate entropy in bits for each.
Copy the one you like: Use the Copy button. Choose a phrase you can actually remember — the whole point of diceware is that you will not need to write it down.
Apply it to your key: When ssh-keygen prompts for a passphrase, paste it. To change an existing key's passphrase run: ssh-keygen -p -f ~/.ssh/id_ed25519, then enter the new value.
Key features
Diceware-style words: Short, common words drawn from a curated list so the result is memorable and quick to type.
Live entropy estimate: Reports approximate bits of entropy from the word count and any appended digit or symbol, so strength is explicit.
Flexible formatting: Word count, separator, capitalization and optional digit/symbol cover common passphrase policies.
Unique per batch: Generate several at once; duplicates within a batch are avoided so you can pick the most memorable.
Secure randomness: Words are selected with crypto.getRandomValues using rejection sampling, so there is no modulo bias.
Runs offline: Everything happens in the browser tab; no passphrase is ever transmitted.
Common use cases
New SSH key protection: Produce a memorable passphrase when generating a fresh id_ed25519 or id_rsa key pair.
Re-encrypting a key: Pick a stronger passphrase to apply with ssh-keygen -p on a key that had a weak one or none.
Incident response: Rotate a possibly-exposed key and set a new strong passphrase immediately.
Master passwords: Choose a memorable high-entropy master password for a password manager or disk encryption.
Team key policy: Give teammates a consistent way to produce passphrases that meet a minimum entropy bar.
Examples
Illustrative shapes; actual words are random on every run.
Five words, dash-separated, capitalized
words: 5, separator: dash, capitalize: on, digit: on
Blue-Bond-Coin-Heal-Cart-5
Roughly 60+ bits depending on list size — memorable yet strong. The trailing digit satisfies policies that require one.
Six words, spaces, no extras
words: 6, separator: space, capitalize: off
river maple token amber quartz drift
A passphrase, not a password — spaces are valid in an SSH passphrase and add to length without hurting memorability.
Four words, no separator, with symbol
words: 4, separator: none, capitalize: on, symbol: on
OtterCedarPixelVault!
Compact for prompts that dislike spaces; four words is the lower end, so lean toward five or more for long-lived keys.
Technical reference
How passphrases are formed and how strong they are:
Style
Diceware — independent random words joined by a separator
Word source
Curated list of short common English words
Entropy per word
log2(list size) bits, added per word; digit/symbol add a few more
Word count
Configurable; 4 is a floor, 5–6 a strong default
Separators
Dash, dot, underscore, space or none
Options
Capitalize words; append a random digit and/or symbol
Randomness source
crypto.getRandomValues with rejection sampling (no modulo bias)
Privacy
Generated locally; never transmitted
Common mistakes to avoid
Leaving an SSH private key with no passphrase
Why it happens: An unencrypted private key is a bearer credential in plaintext. If the file is copied — a lost laptop, a synced backup, an over-broad container image, an accidental git commit — the finder can immediately authenticate as you to every host that trusts the matching public key, with no further work. Convenience (no prompt on use) is the usual reason, but it removes the last line of defense when the key leaks.
How to avoid it: Always set a passphrase on keys that grant real access, and generate a strong one here rather than typing a weak phrase. Use ssh-agent (or the macOS keychain, or gnome-keyring) so you enter the passphrase once per session and are not tempted to drop it for convenience. For automation, use short-lived certificates or a dedicated key with tightly scoped access instead of an unencrypted key.
Picking a passphrase from a song lyric, quote or personal fact
Why it happens: Human-chosen phrases are not random. Song lyrics, movie quotes, book titles and personal details (pet names, birthdays) appear in cracking wordlists and phrase dictionaries, so an attacker guesses them far faster than the phrase's length implies. A memorable sentence can have only 20–30 bits of real entropy despite being long.
How to avoid it: Let the tool choose the words at random from a known list, so the entropy is exactly words × log2(list size) and there is no pattern to exploit. Keep the phrase because it is memorable, not because it means something to you. If a policy forces a digit or symbol, append the random ones this tool adds rather than substituting predictable leetspeak.
Using too few words and assuming it is strong because it is long
Why it happens: Length in characters is a poor proxy for strength in a passphrase. Two random words can be 25 characters but only around 25 bits of entropy, which an offline attacker with a stolen key file can exhaust. The security comes from the number of independent random words, not the character count.
How to avoid it: Choose word count by the entropy estimate the tool shows: aim for at least 60 bits for routine keys and more for keys that guard sensitive systems, which usually means five to seven words. Add a digit or symbol only to satisfy policy; it contributes little compared with one more word.
Frequently asked questions
How many words make a strong SSH passphrase?
As a rule of thumb, five to six random words gives a memorable phrase in the 60–80 bit range, which is strong enough that an offline attacker with your encrypted key file cannot realistically brute-force it. Four words is the practical floor and is acceptable for lower-value keys; use six or more for keys that protect production or sensitive infrastructure. Read the entropy estimate the tool prints and choose a word count that meets your policy.
Are diceware-style passphrases really as strong as random-character passwords?
At equal entropy, yes — a passphrase and a random string of the same bit strength are equally hard to guess. The difference is usability: a five-word passphrase and a twelve-character random password can carry similar entropy, but the passphrase is far easier to remember and type correctly, which means people are less likely to write it down or reuse it. That human factor often makes the passphrase safer in practice.
Is it safe to generate my passphrase in a browser?
This tool generates the passphrase locally with crypto.getRandomValues and never transmits it, so no network request carries your secret. The main caveats are environmental: generate on a machine you trust, not a shared or public computer, and be aware that browser extensions can in principle read page content. For the highest assurance, some people prefer physical dice with a printed diceware list — the resulting phrase is equivalent in strength.
How do I add this passphrase to an existing SSH key?
Use ssh-keygen's change-passphrase mode: run ssh-keygen -p -f ~/.ssh/id_ed25519 (or the path to your key), enter the old passphrase if there is one, then paste the new passphrase twice. The key file is re-encrypted in place; the public key and the key's fingerprint do not change, so nothing on the servers you access needs updating.
Can I use spaces in an SSH passphrase?
Yes. Unlike some legacy password fields, an SSH passphrase accepts spaces and most other characters, so a space-separated word phrase works fine. Choose the separator that you will type most reliably at a prompt — dashes and spaces are both common. The separator itself adds negligible entropy; the words carry the strength.
Does a passphrase protect the key while it is in use?
It protects the key at rest — on disk and in backups. Once you decrypt the key into ssh-agent, the agent holds it in memory for the session so you are not prompted repeatedly, which means an attacker with live access to your running session could still use it. The passphrase's job is to make a stolen key file useless, which is the most common exposure; combine it with a locked screen and a short agent lifetime for defense in depth.