The difference is how the secret is assembled
A password generator selects characters from the types you allow. A passphrase generator selects whole words from a wordlist. The words in a secure generated passphrase are chosen randomly; they do not form a quotation, song lyric, or personal story you picked yourself.
For a visual example only, a phrase might look like orchard-lantern-silver-magnet-cactus-river. Do not use this published example as a password. Once a secret appears in a guide, everyone reading the guide knows it.
| Situation | Useful starting point |
|---|---|
| A password manager fills the login | A long random character password |
| You need to type or remember the secret | A sufficiently long random word passphrase |
| A service has a short length limit | A random password within that limit |
| The service rejects spaces | Choose another allowed separator |
Generate a passphrase in ComplexPass
Open the password and passphrase generator and select the Passphrase tab. The default is six random words joined by hyphens. Use Number of words to adjust the count, and Between words to choose a hyphen, space, period, underscore, or colon that the account accepts.
ComplexPass uses 7,772 entries from an EFF-based long wordlist. The EFF’s passphrase guidance explains why selecting words randomly matters. Our browser generator makes those selections with Web Crypto rather than asking you to roll physical dice.
Which settings add randomness?
Adding another randomly selected word increases the number of possible phrases. Capitalize each word changes the appearance in a predictable way, and using a fixed separator does too. Those fixed choices do not add random bits by themselves.
Add a random number adds two randomly chosen digits at the end. Unique words prevents the same word from appearing twice in one phrase. You can use these settings for readability or a service’s requirements, but the word count remains the main control when you want a larger search space.
The generator’s entropy display describes its settings. It does not predict how long a particular attack will take. A service’s password storage and login protections also affect the risk.
Keep the full result and save it safely
Before saving a passphrase, check the account’s maximum length and accepted characters. Removing half the words to fit a short field removes much of the randomness you selected. If the service has a tight limit, a longer random character password within that limit may fit better.
Use the complete generated result for only one account. A passphrase can be stored in a password manager too; easier reading does not mean it needs to be left on a desk or shared in a message. For more detail, see password length and creating a strong password.