Security Tools

Password Entropy Calculator

Entropy measures how unpredictable a randomly generated secret is. Choose the character set and length, or the size of a word list and the number of words, and see the entropy in bits, the number of possible combinations, and how long it would take to search half of them at different attack speeds. You can also type a password to compare its theoretical maximum with a pattern-aware estimate.

  • Runs in your browser
  • No sign-up
  • Free to use
Calculate from
Characters used

Overrides the boxes, for example 16 for hexadecimal or 58 for Base58.

How to use Password Entropy Calculator

  1. Choose whether to calculate from characters, words or a password.
  2. Enter the character set and length, or the word list size and word count.
  3. Read the entropy in bits and the verdict.
  4. Compare the search times for different attack speeds.

Password Entropy Calculator features

Characters or words

Random passwords and Diceware-style passphrases.

Any alphabet

Enter the number of symbols directly: 16 for hex, 58 for Base58.

Combinations

The size of the search space as a power of ten.

Search times

At online and offline guessing speeds.

Reality check

For typed passwords, shows the pattern-aware estimate alongside.

Shows the formula

Bits = length × log₂(alphabet size).

When to use Password Entropy Calculator

  • Choosing a length for generated passwords or API keys.
  • Comparing a passphrase with a random password.
  • Setting a minimum for a password policy.
  • Explaining entropy in a security course.

Password Entropy Calculator FAQ

What is password entropy?

For a secret chosen uniformly at random, entropy is log₂ of the number of possible values. A 12-character password from 62 letters and digits has 12 × log₂(62) ≈ 71.5 bits.

How many bits are enough?

For online accounts protected by rate limiting, 50–60 bits is ample. Against offline attacks on stolen hashes, aim for at least 70–80 bits. Cryptographic keys use 128 bits or more.

Why does my own password score lower in the strength checker?

Because entropy assumes every character was chosen at random. People choose words, names and patterns, which attackers try first, so real strength is far lower than the theoretical maximum.

Is a passphrase as strong as a password?

Five words from a 7,776-word list give 64.6 bits, comparable to an 11-character random password from letters and digits, and are much easier to remember.

What does “half the space” mean?

On average an attacker finds a random secret after searching half of all possibilities.

Does adding symbols help much?

A little per character: 94 symbols give 6.55 bits per character against 5.95 for letters and digits. Adding length helps more than enlarging the alphabet.

Bits as a measure of unpredictability

Entropy, in the sense used for passwords and keys, counts the number of yes-or-no questions needed to identify a secret chosen at random. Each bit doubles the number of possibilities: 40 bits is about a trillion, 80 bits about a trillion trillion. Because the scale is logarithmic, small increases in bits mean enormous increases in work for an attacker.

For random secrets the calculation is exact and simple: the number of choices per position, raised to the number of positions. A character set of 62 symbols gives log₂(62) ≈ 5.95 bits per character; a word list of 7,776 entries gives 12.9 bits per word. Length multiplies, which is why longer secrets gain strength so quickly.

The calculation is only valid when every choice is random and independent. A password a person made up does not qualify, because human choices are concentrated on a small, predictable part of the space. That is why this page reports entropy for the generated case and links to the pattern-aware Password Strength Checker for real passwords.

Turning bits into time requires an assumption about the attacker’s speed. Online guessing is slow and usually limited; offline attacks on stolen hashes can reach billions of guesses per second when sites use fast, unsalted hashes. Sizing secrets for the offline case keeps them safe even if a service is breached.

Other useful tools