# Passphrase — Randomly

> 12.9 bits per word, from a list of 7,776 — and zero for the capital letters. One of 63 generators at [Randomly](https://randomly.cluxnei.dev), a library of random generators seeded from verifiable real-world entropy. Free HTTP API, no key, no signup.

## `words.passphrase` — Passphrase

12.9 bits per word, from a list of 7,776 — and zero for the capital letters.

| | |
|---|---|
| **Key** | `words.passphrase` |
| **Module** | `words` |
| **Version** | `1` — a permalink carries this, and a replay against a different version returns `409` rather than something else |
| **Formats** | `application/json`, `text/plain` |
| **Studio** | https://randomly.cluxnei.dev/g/words/passphrase |
| **API** | `GET https://randomly.cluxnei.dev/api/v1/g/words.passphrase` |

`value` is the result itself — one value, or a list of them; `display` is the same thing rendered as a single human-readable string.

**Sensitive.** This generator produces secrets, so it is given no token and no shareable
permalink, and `/api/v1/replay` returns `404` for it. A secret with a replayable URL is
not a secret. Nothing is logged or stored either way — there is no database.

| Parameter | Type | Default | Accepts | What it does |
|---|---|---|---|---|
| `words` | int | `6` | `4` – `12` | Words — Six words is 77.5 bits. Four is 51.7 — fine for a laptop login, not for a password manager. |
| `list` | enum | `large` | `large`, `short` | Wordlist |
| `separator` | enum | `dash` | `dash`, `space`, `dot`, `underscore`, `none` | Separator |
| `capitalise` | bool | `false` | `true`, `false` | Capitalise each word — Adds zero bits. It is a rule, and the attacker has the rule too. |
| `append_number` | bool | `false` | `true`, `false` | Append a number — Adds 6.6 bits, because this one is actually drawn at random. |

Out-of-range numbers are **clamped, not rejected**, so a request never fails for being
ambitious — but it may not do what you meant. Unknown keys are dropped and missing ones
fall back to the defaults above.

```bash
curl -s 'https://randomly.cluxnei.dev/api/v1/g/words.passphrase?words=6&list=large&separator=dash' -H 'Accept: text/plain'
```

## The receipt

Every result carries one, naming the physical source of the randomness and linking to the
third party's own record of it:

```json
"receipt": {
  "source": "seismic",
  "source_label": "USGS Seismic Feed",
  "class": "C",
  "caveat": "Carries only tens of bits of genuine surprise. Always mixed with the OS CSPRNG.",
  "narrative": "A magnitude 3.6 earthquake, 67 km N of Culebra, Puerto Rico, 39.6 km down — 52 minutes ago.",
  "proof_url": "https://earthquake.usgs.gov/earthquakes/eventpage/us7000th33",
  "mixed_with_csprng": true,
  "degraded": false
}
```

Pick the source with `?source=`, or leave it at the default `auto`:

- **Class A** (Cryptographic) — `csprng`, `anu-qrng`, `random-org`
- **Class B** (Public beacon) — `nist-beacon`, `drand`, `bitcoin`. Published openly — anyone can look this value up after the fact.
- **Class C** (Observational) — `seismic`, `space-weather`, `atmosphere`, `iss`. Carries only tens of bits of genuine surprise. Always mixed with the OS CSPRNG.

## More

- [The full API contract](https://randomly.cluxnei.dev/api.md)
- [Everything in one file](https://randomly.cluxnei.dev/llms-full.txt)
- [The catalogue as JSON](https://randomly.cluxnei.dev/api/v1/generators)
- [This generator in the browser](https://randomly.cluxnei.dev/g/words/passphrase)
