Password Entropy Calculator
Estimate a password's entropy in bits from its length and character set, with offline crack-time context. The password is analysed locally and never stored or sent.
Loading calculator…
What this tool does
Estimate a password's entropy in bits from its length and character set, with offline crack-time context. The password is analysed locally and never stored or sent. This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.
How to use the Password Entropy Calculator
- Enter or select password to analyse.
- Read the calculated result; change any measurement to compare alternatives.
Formula
Entropy = length x log2(charset size), where charset size sums the character classes present: lowercase 26, uppercase 26, digits 10, symbols 33, space 1, other Unicode 100.
- password
- Password to analyse
This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.
Worked example
For password entropy calculator, the following measurements illustrate the exact method: Password to analyse: correct horse battery staple.
Inputs
- Password to analysecorrect horse battery staple
Result
- Entropy (bits)133.1
- Length (characters)28
- Character set size27
- Average guesses to crack2^132.1 ≈ astronomical
- Offline crack time at 10 billion guesses/sec1.90e+13 trillion years
- StrengthExcellent (if truly random)
Results explained
- Entropy (bits)
- Entropy (bits) from the formula above. This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.
- Length (characters)
- Length (characters) from the formula above. This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.
- Character set size
- Character set size from the formula above. This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.
- Average guesses to crack
- Average guesses to crack from the formula above. This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.
- Offline crack time at 10 billion guesses/sec
- Offline crack time at 10 billion guesses/sec from the formula above. This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.
- Strength
- Strength from the formula above. This is an upper-bound estimate that assumes every character was chosen independently and uniformly at random. Human-chosen passwords have far less real entropy — a password manager's generated passwords match this model, memorable phrases do not.
Frequently asked questions
At least 60-70 bits for accounts protected by rate-limited online login, and 100+ bits for master passwords or keys that could be attacked offline. Each extra bit doubles an attacker's work.
Entropy = length x log2(alphabet size). A 12-character password drawn from all 95 printable ASCII characters has about 12 x 6.57 = 79 bits — if the characters were truly random.
The formula assumes random, independent characters. Dictionary words, names, dates and keyboard patterns collapse the search space dramatically, so human-invented passwords are much weaker than the raw bit count suggests. The estimate here is a best case.
On average an attacker tries half the space: 2^(entropy-1) guesses. The tool shows that time at 10 billion guesses per second, a plausible offline rate against a fast hash — slow password hashes (bcrypt, Argon2id) cut the rate by orders of magnitude.
Analysis runs entirely in your browser and the value is never stored or transmitted. As a habit, prefer analysing a similar-but-not-identical password rather than a live credential in any tool.