Home / Password & Passphrase Tools / Password Combination Calculator
Password & Passphrase Tools

Password Combination Calculator

Calculate exact random-generator keyspace, requirement-aware combinations, theoretical entropy and exhaustive-search timing assumptions without entering a real password.

recipe math · no real password input

Password Search-Space & Policy Studio

Model the exact number of outputs a random generator or password policy permits, account for minimum character-class requirements, compare policies, and inspect theoretical entropy without entering a secret.

Exact BigInt combinatorics

Random-generator policy

26 choices
26 choices
10 choices
33 printable ASCII symbols
Minimum-class requirements use exact inclusion–exclusion over disjoint character groups. “Additional distinct choices” are assumed to be unique and non-overlapping with the standard groups.
—Exact combinations
—Scientific view
—Theoretical entropy
—Average exhaustive time
—Worst-case exhaustive time
—Illustrative rate

Length sensitivity

LengthCombinationsBitsAvg exhaustive time

Evidence & handoff

Requirements change the count

If uppercase, digits or symbols are mandatory, simply using pool^length overcounts outputs that violate the policy. Inclusion–exclusion removes those invalid strings exactly.

Entropy is a model assumption

log₂(search space) is an upper bound only when outputs are uniformly distributed over the modeled space. Human selection is rarely uniform.

Length compounds quickly

Each additional random character multiplies the space by the pool size. The length table makes that compounding visible without requiring a real password.

Keyspace & exhaustive-search planner

Translate alphabet size and length into entropy and theoretical exhaustive-search times.

Security math
ScenarioCombinationsEntropyAvg. exhaustive time
Use the tool above, then refresh this audit.

Count a generation space, not a real secret

A password-combination calculator is most reliable when it models the recipe that produces a random secret: the available choices, the length and any minimum character-class rules. This page never needs the finished password. Keeping the model at the recipe level avoids turning a theoretical calculator into a place where users paste sensitive credentials.

Uniform pools use powers

If each of L positions independently draws from the same pool of P choices, there are exactly P^L possible strings. The calculator keeps this integer as a BigInt so large spaces are not rounded into floating-point approximations.

Required groups need inclusion–exclusion

A policy such as “use lowercase, uppercase and digits, with at least one uppercase and one digit” has fewer valid outputs than the unrestricted 62-character pool. The studio counts the valid strings by inclusion–exclusion: it subtracts strings missing each required group, then restores overlaps that were subtracted more than once.

Position-specific recipes multiply choices

If each position has its own number of possibilities, multiply the per-position counts. This is useful for structured random codes and format policies without relying on attack-tool mask syntax.

Entropy is only as good as the random model

The displayed bit value is log₂(exact search space). It is an upper bound for a generator that samples uniformly from the modeled space. Dictionary words, reused passwords, names, dates, keyboard patterns and leaked credentials are not uniformly random and can be guessed far earlier than the bit count suggests.

Crack-time figures are illustrative math

The timing panel divides average or worst-case exhaustive guesses by a selected guesses-per-second assumption. Real systems differ by authentication throttling, password-hash design, hardware, distributed resources and attack strategy. Treat the output as a way to compare policies—not a guarantee that a specific account or password will resist attack for that long.

Practical guide and verification

Separate search space from password strength

Character-pool size raised to the password length gives a theoretical combination count only when each position is chosen independently and uniformly. Human-created passwords, reused patterns and predictable substitutions occupy a much smaller effective search space.

Match the pool to the generator that produced the password

Do not count uppercase, symbols or digits merely because they are allowed by a site. Include only characters the generator could actually choose at each position. A wrong pool size can change the estimated search space by many orders of magnitude.

Guess-rate scenarios are assumptions, not guarantees

Online services can throttle, lock accounts or require additional factors, while an offline hash attack depends on the hash function, work factor and hardware. Keep the selected guesses-per-second scenario visible with the estimate rather than presenting one time as universal.

Use logarithms for very large spaces

Combination counts become too large to interpret directly. Bits of entropy, log10 combinations or scientific notation make different lengths and pools easier to compare without implying that every theoretical combination is equally likely in real user behavior.

Prefer generated unique passwords over manually engineered ones

A password manager or cryptographically secure generator can sample the intended space more reliably than a human can. The calculator is useful for comparing design choices, but it does not inspect reuse, breaches, phishing exposure or account recovery weaknesses.

Search by task, tool name, or category. Press Esc to close.
Start typing to find a tool.