The Password Game is an online puzzle created by Neal Agarwal that tests your ability to follow increasingly strict password rules. It's not a video game in the traditional sense—there's no shooting, jumping, or collecting items. Instead, you're building a single password that must satisfy a growing list of requirements, with each new rule adding another layer of challenge.
Free Guide to Taking Screenshots on Dell Chromebooks →
The game launched in 2024 and became unexpectedly popular because it taps into something real: password creation has become genuinely complicated. Tech companies and websites constantly demand stronger, stranger passwords, and most people don't fully understand why these rules exist or what they're actually protecting. The Password Game takes those frustrating real-world rules and turns them into a playable experience that teaches you something genuine about password security in the process.
You start with five basic rules and unlock new ones as you progress through each level. The rules don't follow a logical progression you might expect. Some seem silly (your password must contain a food emoji), while others relate to actual security concerns (your password must be at least 8 characters). This mix of the practical and the absurd is intentional—it mirrors how password requirements actually feel when you're trying to create one.
The game is entirely free, browser-based, and requires no account creation. You simply visit the website and start playing. There's no timer, no score tracking between sessions, and no pressure. You can spend five minutes or five hours trying to solve it. This is important context because the game itself isn't trying to teach you how to create passwords for your own accounts—it's teaching you how password rules work and why they exist by letting you experience them directly.
Takeaway: The Password Game is a free educational puzzle that uses humor and increasingly difficult rules to show you how password requirements actually function in the real world.
Every player starts with the same five rules that form the foundation of real password security. Understanding these baseline requirements reveals why websites ask for them.
Learn About BMV Saturday Hours and Visit Planning →
Rule 1 is length: your password must contain at least 5 characters. This rule exists because passwords that are too short can be cracked by computers very quickly. A five-character password made only of lowercase letters can theoretically be tested in minutes. This is why every serious website asks for a minimum length—usually 8 characters in real life, though the game starts at 5 to let you ease in.
Rule 2 requires uppercase letters. When you add uppercase to your password, you're increasing what's called the "character space"—the total number of possible combinations a computer would need to try. If a password uses only lowercase letters, there are 26 possible characters at each position. Add uppercase, and now there are 52. This dramatically increases cracking time.
Rule 3 demands numbers. Numbers further expand the character space to 62 possibilities (26 lowercase + 26 uppercase + 10 digits). From a mathematical standpoint, this rule makes passwords exponentially harder to crack through brute force attacks, where a computer simply tries every possible combination.
Rule 4 introduces special characters—symbols like !, @, #, $, and others. This rule adds another 30+ possibilities at each position, depending on which special characters the system accepts. Real password requirements often insist on special characters for this reason: they're the most effective way to increase complexity without making passwords excessively long.
Rule 5 requires that your password not contain the word "password." This seems obvious now, but it addresses a real security problem: many people choose passwords that literally contain the word "password." The rule forces you to break that habit and think about your own actual password creation process.
Takeaway: The first five rules teach that password strength comes from length, character variety (uppercase, lowercase, numbers, symbols), and avoiding predictable words—the same principles used in actual password requirements.
As you progress past Rule 5, the requirements become increasingly specific and creative. This is where the game shifts from teaching pure security concepts to illustrating how absurdly detailed password rules can become in the real world.
Free Guide to Online Membership and Dues Payment Portals →
One of the mid-game rules requires that your password contain a food emoji. This rule doesn't enhance security in any technical sense—a computer cracking your password doesn't care whether you used 🍕 or 🥗. Instead, this rule teaches you something important: password requirements often exist not for security reasons but because of how software was designed or what a company decided to enforce. Some sites require special characters not because they mathematically need them, but because their password validator was programmed that way.
Another rule involves mathematical operations or sequences within your password itself. For example, some versions require that your password contain numbers that are in ascending order, or that math formulas evaluate to specific values when calculated. These rules have no security purpose whatsoever—they exist purely to make the puzzle harder. In real life, you rarely encounter such rules, but they're used here to show how password requirements can become irrational and frustrating.
Some middle rules involve wordplay or letter patterns. You might need your password to contain words that rhyme, or letters that appear in alphabetical order. Again, these serve no security function. They're obstacles that force you to think differently about how letters and words combine within a single string of text.
The middle rules typically occupy positions 6 through 12, depending on how the game has been updated. Each rule builds on previous ones—you're not replacing Rule 1, you're adding to it. By this point in the game, players often realize that creating a password that satisfies 10+ conflicting requirements is genuinely difficult, even with the answer right in front of you on the screen.
Takeaway: Middle-stage rules reveal that not all password requirements serve security purposes—some exist due to arbitrary design choices, demonstrating why real-world password creation often feels unnecessarily complicated.
The later rules in The Password Game push the concept to its logical extreme. These rules typically involve password checking against external information, mathematical constraints that require real calculation, and requirements that seem to actively conflict with each other.
Learn About Pennsylvania Inspection and Emissions Testing Fees →
One advanced rule requires that your password contain a number that matches the current day of the week or month. This introduces a dynamic element—your password can't simply stay the same; it changes depending on when you play. In cybersecurity terms, this is similar to time-based authentication systems, though applied to password creation itself rather than access validation.
Another rule commonly found in the advanced section requires that your password's length, when multiplied by the number of special characters, equals a specific value. This forces mathematical thinking and reverse-engineering. You're no longer just following instructions; you're solving equations to determine what your password must contain.
Some advanced rules involve checking your password against external resources. The game might require that a specific word in your password is a valid English word found in a dictionary, or that a string of letters corresponds to coordinates on Earth, or that numbers represent something meaningful. These rules teach you how passwords can be validated against databases and real-world information, not just character patterns.
The psychological breaking point usually happens around rule 15-16 for most players. At this stage, you might have 15-20 simultaneous requirements to track. A password that satisfies rules 1-10 might violate rule 14. Fixing rule 14 might break rule 7. The game becomes less about security education and more about problem-solving under extreme constraint—which actually teaches something valuable about why password requirements are kept simpler in the real world. Websites know that if they demand too many conflicting rules, people will either give up or write their passwords on sticky notes.
Takeaway: Advanced rules show both the limits of password complexity and why real-world security standards must balance toughness with usability—a lesson illustrated through frustration.
While The Password Game is designed to be entertaining and increasingly absurd, it teaches genuine information about actual cybersecurity practices and why passwords have become complicated.
Learn About Training Australian Shepherds →
The game's foundation reflects NIST (National Institute of Standards and Technology) guidelines, which recommend passwords be at least 8 characters long with mixed character types. Every legitimate website using password security should follow these basic principles. The game starts here, giving you the framework that governs password creation across the internet.
The inclusion of special
This guide is for general information only and is not medical, financial, legal, or other professional advice. For decisions specific to your situation, consult a qualified professional. See our Editorial Policy.