Skip to content
FlexibleToolsAI
Security Toolkit · 100% Client-Side Private

Password Entropy Calculator

Measure password strength the way security engineers do — in bits of entropy. See the classic formula (length × log2 of the character pool), a realistic estimate that accounts for words, dates and patterns, and what those bits mean in time to crack.

Entropy (bits) = length × log2(pool size), where the pool is the number of possible characters: 26 for lowercase, 62 for letters and digits, 95 for all printable ASCII. That formula is only accurate for randomly generated passwords; for human-chosen ones this calculator also gives a realistic estimate that discounts dictionary words, sequences and dates.

Checked in your browser. The password is never sent anywhere; the optional breach check sends only the first 5 characters of its SHA-1 hash (k-anonymity).

Entropy of randomly generated passwords

Character set8 chars/words12 chars/words16 chars/words20 chars/words
Digits only (0–9) (10)27 bits40 bits53 bits66 bits
Lowercase (a–z) (26)38 bits56 bits75 bits94 bits
Letters (a–z, A–Z) (52)46 bits68 bits91 bits114 bits
Letters + digits (62)48 bits71 bits95 bits119 bits
All printable ASCII (95)53 bits79 bits105 bits131 bits
Diceware word (EFF list) (7776)103 bits155 bits207 bits258 bits

Entropy (bits) = length × log2(pool size). Each extra bit doubles the guesses needed. 60–80+ bits is strong for online accounts; use 80+ for encryption keys and master passwords.

Zero Server Uploads

Files process in local RAM

Instant WASM Speed

No waiting queues or lags

Unlimited Batching

Convert files without limits

Suggest a Feature or Improvement for Password Entropy Calculator

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use Password Entropy Calculator

  1. 1Type a password or passphrase.
  2. 2Compare the naive entropy with the realistic estimate.
  3. 3Check the crack times for each attack scenario.
  4. 4Use the reference table to pick a length for generated passwords.

The entropy formula

For a password generated uniformly at random, entropy H = L × log2(N), where L is the length and N the number of possible symbols. A random 12-character password from 62 alphanumerics has 12 × 5.95 ≈ 71 bits. Each bit doubles the attacker's work, so 80 bits is a thousand times harder than 70.

Diceware passphrases use the same maths with words: each word from a 7,776-word list adds log2(7776) ≈ 12.9 bits.

Why human passwords have less

“Summer2024!” scores about 72 bits by the naive formula, but an attacker tries season-plus-year patterns early, so its real entropy is closer to 20 bits. That's why this calculator shows both. For guaranteed entropy, generate passwords with the Strong Password Generator.

Frequently Asked Questions

How many bits of entropy is a strong password?

Roughly: under 40 bits is weak, 60 bits is reasonable for online accounts protected by rate limiting, and 80+ bits is strong enough for master passwords and encryption keys.

Does a longer password always have more entropy?

Only if the extra characters are unpredictable. Repeating a word or adding “123” adds length but very little entropy.

Is my data sent to your server?

No. This tool runs entirely in your browser using the Web Crypto API and JavaScript. Nothing you type or generate is uploaded, logged or stored.

Guides & Tutorials

Related Tools