Tools · Entropy

Your password's entropy, calculated.

Entropy is unpredictability measured in bits. Enter a password to see the math worked out — character pool, length, and the resulting bits — all on your device.

a–z (26) A–Z (26) 0–9 (10) !@#$ (33)
Length0 characters
Character pool size0 symbols
Bits per character (log2 pool)0
Total entropy (length × bits/char)0 bits
—

Calculated locally in your browser. No network, no logging, no telemetry.

The entropy formula

length × log₂(pool)

Why log₂?

Each bit doubles the guesses an attacker needs. A pool of 95 symbols is about log2(95) ≈ 6.6 bits per character, so every character you add multiplies the difficulty by ~95.

Random is the assumption

This math only holds if each character is chosen independently and uniformly. That’s precisely what a CSPRNG does and a human brain doesn’t — which is why a generated password’s real entropy matches its theoretical entropy.

Passphrases count words

For passphrases the unit of randomness is the word, not the character: entropy is words × log2(wordlist size). A 6-word passphrase from a 1,193-word list is ~61 bits. Build one with the passphrase generator.

Password Entropy Calculator FAQ

Common questions

What is password entropy?

Entropy is a measure of unpredictability, expressed in bits. Each additional bit doubles the number of guesses needed to brute-force the password. It is calculated as length × log2(character pool size) for a randomly chosen password.

How is the character pool size determined?

The pool is the count of distinct symbols an attacker must consider: 26 for lowercase, 26 for uppercase, 10 for digits, and 33 for common ASCII punctuation. We add the sizes of whichever classes appear in your password.

Does this assume my password is random?

Yes — the length × log2(pool) formula assumes each character is chosen independently and uniformly. A human-chosen password with dictionary words or patterns has much lower real entropy than this formula suggests, which is exactly why generated passwords are stronger.

How many bits should I aim for?

≥80 bits is strong against offline brute-force in 2026, and ≥100 bits is future-proof. A 14–16 character password using all four character classes, chosen randomly, gets you there.

Ready for the full vault?

Stop reusing. Start sealing.

Apex Password stores every credential end-to-end encrypted, on your device. The relay never sees plaintext.