xkcdpass
Generate secure multiword passwords/passphrases, inspired by XKCD
Decision gist · record as of 2026-08-14
Yes. xkcdpass is a stable, dependency-free tool for generating strong passphrases with no security vulnerabilities on record. It is well-suited for anyone who prefers memorable multi-word passwords over random character strings. The aging maintenance status (215 days since last release) is not a blocker for a mature utility with no active bugs, but verify whether the project's pace aligns with your support expectations.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.6 or later.
- Low friction: pure Python wheel with no runtime dependencies.
- Maintenance status is aging (last release 215 days ago, last commit 2026-01-24), but the package is marked Production/Stable and the repository remains active with 1431 stars.
License · maintenance · safety
BSD-3-Clause (permissive) — BSD-3-Clause is permissive and poses no restriction on commercial or private use. Word lists included carry mixed licenses (CC BY 3.0, public domain, GPL, BSD-3); the package documentation clarifies each list's provenance.
last release 2026-01-11 (215 days) · last repo commit 2026-01-24 · 1,431 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 294,262 downloads/mo, #7,949 on PyPI
Alternatives
Verify before relying
$ pip install xkcdpass
$ xkcdpass
> correct horse battery staple
Or with options:
$ xkcdpass --count=2 --numwords=4 --delimiter='-'
> word-word-word-word
> word-word-word-word- Whether the cryptographically secure RNG requirement is enforced by default or requires explicit opt-in beyond the --allow-weak-rng flag.
- Whether the package is actively maintained or in maintenance-only mode given the 215-day gap since last release.
What it is and what it does
xkcdpass is a command-line tool that generates strong passphrases by randomly combining words from a word list, inspired by the XKCD 936 comic. It ships with multiple built-in word lists (EFF-long, EFF-short, and variants in Spanish, Finnish, Italian, German, Norwegian, French, Portuguese, and Swedish) and supports custom word files. The tool is designed to produce memorable yet cryptographically strong passwords suitable for diceware-style passphrase generation.
The package offers fine-grained control over passphrase generation: you can specify word count, minimum and maximum word length, delimiter characters, case transformation rules (lower, upper, alternating, random, capitalize, as-is), and acrostic constraints to force the first letters to spell a chosen word. It runs as a standalone CLI with no external runtime dependencies, making it lightweight and easy to integrate into scripts or password workflows.
Use it for
- Generate a memorable passphrase for a personal password manager or high-security account.
- Create multiple candidate passphrases interactively and select the one you prefer.
- Enforce passphrase structure (e.g., acrostic spelling, specific delimiters) for compliance or organizational standards.
- Integrate passphrase generation into shell scripts or automation workflows via command-line arguments.
- Use custom word lists in other languages or domains for domain-specific passphrase generation.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
xkcdpass is a stable, dependency-free tool for generating strong passphrases with no security vulnerabilities on record. It is well-suited for anyone who prefers memorable multi-word passwords over random character strings. The aging maintenance status (215 days since last release) is not a blocker for a mature utility with no active bugs, but verify whether the project's pace aligns with your support expectations.
Install
xkcdpass on PyPI
Before you install
Low friction: pure Python wheel with no runtime dependencies. Maintenance status is aging (last release 215 days ago, last commit 2026-01-24), but the package is marked Production/Stable and the repository remains active with 1431 stars.
Requires Python 3.6 or later.
License in practice
BSD-3-Clause is permissive and poses no restriction on commercial or private use. Word lists included carry mixed licenses (CC BY 3.0, public domain, GPL, BSD-3); the package documentation clarifies each list's provenance.
Quickstart
$ pip install xkcdpass
$ xkcdpass
> correct horse battery staple
Or with options:
$ xkcdpass --count=2 --numwords=4 --delimiter='-'
> word-word-word-word
> word-word-word-word
Verify before relying
- Whether the cryptographically secure RNG requirement is enforced by default or requires explicit opt-in beyond the --allow-weak-rng flag.
- Whether the package is actively maintained or in maintenance-only mode given the 215-day gap since last release.
Package facts
| License | BSD-3-Clause permissive |
| Python support | Supports the current Python release >=3.6 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Aging 215 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 294,262 / month, #7,949 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleOperating System :: OS IndependentProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: xkcdpass-1.30.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “passphrase generator”
- xkcdpassGenerates strong, memorable passphrases by randomly selecting words…
- dicewarediceware generates memorable passphrases by randomly selecting words…
- pyragepyrage provides Python bindings to the Rust implementation of age,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also diceware · password-strength · mnemonic · wonderwords · random-password-generator · codenamize · friendlywords · rstr · coolname · randomname