How Many Bits of Entropy Is Your Password?

Type a password (or a length) and pick the character pool. This tool computes Shannon entropy in bits and estimates offline crack time — entirely in your browser, nothing is sent anywhere.

lowercase (26) uppercase (26) digits (10) symbols (33)

Default 1e11 ≈ a single high-end GPU rig against fast unsalted hashes (e.g. NTLM/MD5). Slow salted hashes (bcrypt) are far lower.

Pool size (R)
—
Length (L)
—
Entropy
—
Combinations
—
Estimated offline crack time (avg, ½ keyspace)
—
—

How the entropy is calculated

Password entropy measures how unpredictable a secret is, expressed in bits. Assuming each character is drawn uniformly and independently from a pool of R possible symbols, a password of length L has RL equally likely values. The information content — the entropy — is the base-2 logarithm of that count:

H = L × log2(R)  bits   (equivalently H = log2(RL))

This tool detects which character classes you actually used and sums their sizes to get R: 26 lowercase, 26 uppercase, 10 digits, and 33 printable ASCII symbols — a maximum pool of 95. So an 8-character password using lowercase + digits draws from R = 36, giving H = 8 × log₂(36) ≈ 41.4 bits. Each extra character adds a fixed log₂(R) bits, which is why length dominates strength far more than swapping in a single symbol.

To turn bits into time, the calculator computes the keyspace 2H and assumes an attacker must search, on average, half of it before a hit. Dividing by your guess rate yields the expected offline cracking time:

avg seconds = (2H / 2) / guesses-per-second

One important honesty note for bug-bounty and pentest work: this is the theoretical maximum entropy for a random string of that composition. Real human passwords — dictionary words, dates, l33t substitutions, keyboard walks — are not uniformly random, so their effective entropy is much lower than the formula suggests. Tools like zxcvbn model those patterns; this calculator gives the upper bound. Use it to compare composition policies and to sanity-check why an 18-character random passphrase beats a clever 8-character one every time.

Related Tools

CVSS Score Calculator API Scanner