Password Entropy Calculator

Estimate a password's entropy in bits from its length and character set, with offline crack-time context. The password is analysed locally and never stored or sent.

Loading calculator…

What this tool does

Estimate a password's entropy in bits from its length and character set, with offline crack-time context. The password is analysed locally and never stored or sent. This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.

How to use the Password Entropy Calculator

  1. Enter or select password to analyse.
  2. Read the calculated result; change any measurement to compare alternatives.

Formula

Entropy = length x log2(charset size), where charset size sums the character classes present: lowercase 26, uppercase 26, digits 10, symbols 33, space 1, other Unicode 100.
password
Password to analyse

This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.

Worked example

For password entropy calculator, the following measurements illustrate the exact method: Password to analyse: correct horse battery staple.

Inputs

  • Password to analysecorrect horse battery staple

Result

  • Entropy (bits)133.1
  • Length (characters)28
  • Character set size27
  • Average guesses to crack2^132.1 ≈ astronomical
  • Offline crack time at 10 billion guesses/sec1.90e+13 trillion years
  • StrengthExcellent (if truly random)

Results explained

Entropy (bits)
Entropy (bits) from the formula above. This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.
Length (characters)
Length (characters) from the formula above. This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.
Character set size
Character set size from the formula above. This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.
Average guesses to crack
Average guesses to crack from the formula above. This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.
Offline crack time at 10 billion guesses/sec
Offline crack time at 10 billion guesses/sec from the formula above. This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.
Strength
Strength from the formula above. This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.

Frequently asked questions

At least 60-70 bits for accounts protected by rate-limited online login, and 100+ bits for master passwords or keys that could be attacked offline. Each extra bit doubles an attacker's work.

Entropy = length x log2(alphabet size). A 12-character password drawn from all 95 printable ASCII characters has about 12 x 6.57 = 79 bits — if the characters were truly random.

The formula assumes random, independent characters. Dictionary words, names, dates and keyboard patterns collapse the search space dramatically, so human-invented passwords are much weaker than the raw bit count suggests. The estimate here is a best case.

On average an attacker tries half the space: 2^(entropy-1) guesses. The tool shows that time at 10 billion guesses per second, a plausible offline rate against a fast hash — slow password hashes (bcrypt, Argon2id) cut the rate by orders of magnitude.

Analysis runs entirely in your browser and the value is never stored or transmitted. As a habit, prefer analysing a similar-but-not-identical password rather than a live credential in any tool.