Requirements change the count
If uppercase, digits or symbols are mandatory, simply using pool^length overcounts outputs that violate the policy. Inclusion–exclusion removes those invalid strings exactly.
Calculate exact random-generator keyspace, requirement-aware combinations, theoretical entropy and exhaustive-search timing assumptions without entering a real password.
Model the exact number of outputs a random generator or password policy permits, account for minimum character-class requirements, compare policies, and inspect theoretical entropy without entering a secret.
Enter one positive pool size per position. Example: 26,26,26,10,10 means three positions with 26 independent choices followed by two positions with 10 choices. The studio multiplies the counts exactly.
| Policy | Length | Pool | Required groups | Combinations | Entropy | Avg exhaustive time |
|---|
| Length | Combinations | Bits | Avg exhaustive time |
|---|
If uppercase, digits or symbols are mandatory, simply using pool^length overcounts outputs that violate the policy. Inclusion–exclusion removes those invalid strings exactly.
log₂(search space) is an upper bound only when outputs are uniformly distributed over the modeled space. Human selection is rarely uniform.
Each additional random character multiplies the space by the pool size. The length table makes that compounding visible without requiring a real password.
Translate alphabet size and length into entropy and theoretical exhaustive-search times.
| Scenario | Combinations | Entropy | Avg. exhaustive time |
|---|
A password-combination calculator is most reliable when it models the recipe that produces a random secret: the available choices, the length and any minimum character-class rules. This page never needs the finished password. Keeping the model at the recipe level avoids turning a theoretical calculator into a place where users paste sensitive credentials.
If each of L positions independently draws from the same pool of P choices, there are exactly P^L possible strings. The calculator keeps this integer as a BigInt so large spaces are not rounded into floating-point approximations.
A policy such as “use lowercase, uppercase and digits, with at least one uppercase and one digit” has fewer valid outputs than the unrestricted 62-character pool. The studio counts the valid strings by inclusion–exclusion: it subtracts strings missing each required group, then restores overlaps that were subtracted more than once.
If each position has its own number of possibilities, multiply the per-position counts. This is useful for structured random codes and format policies without relying on attack-tool mask syntax.
The displayed bit value is log₂(exact search space). It is an upper bound for a generator that samples uniformly from the modeled space. Dictionary words, reused passwords, names, dates, keyboard patterns and leaked credentials are not uniformly random and can be guessed far earlier than the bit count suggests.
The timing panel divides average or worst-case exhaustive guesses by a selected guesses-per-second assumption. Real systems differ by authentication throttling, password-hash design, hardware, distributed resources and attack strategy. Treat the output as a way to compare policies—not a guarantee that a specific account or password will resist attack for that long.
Character-pool size raised to the password length gives a theoretical combination count only when each position is chosen independently and uniformly. Human-created passwords, reused patterns and predictable substitutions occupy a much smaller effective search space.
Do not count uppercase, symbols or digits merely because they are allowed by a site. Include only characters the generator could actually choose at each position. A wrong pool size can change the estimated search space by many orders of magnitude.
Online services can throttle, lock accounts or require additional factors, while an offline hash attack depends on the hash function, work factor and hardware. Keep the selected guesses-per-second scenario visible with the estimate rather than presenting one time as universal.
Combination counts become too large to interpret directly. Bits of entropy, log10 combinations or scientific notation make different lengths and pools easier to compare without implying that every theoretical combination is equally likely in real user behavior.
A password manager or cryptographically secure generator can sample the intended space more reliably than a human can. The calculator is useful for comparing design choices, but it does not inspect reuse, breaches, phishing exposure or account recovery weaknesses.