Password Strength
Estimate password entropy and crack time.
Charset-pool entropy only. Shows classes used and a rough offline crack estimate. Not a breach check.
What Password Strength does
Charset-pool entropy only. Shows classes used and a rough offline crack estimate. Not a breach check.
The interactive controls for Password Strength load after this article so crawlers still read the instructions. Path /crypto/password-strength is the canonical address. Work happens on this device; Tool-You does not take a copy of the file or pasted text for Password Strength.
How to use Password Strength
- Keep this tab on Password Strength (/crypto/password-strength). Pasting into the wrong Crypto tool (for example Password Generator) changes the job.
- Paste or type the input Password Strength expects. Path hint: crypto · password strength. Estimate password entropy and crack time.
- Apply the Password Strength action only. HMAC-SHA256 is a different transform (HMAC-SHA256 hex and Base64; optional uppercase.). Charset-pool entropy only. Shows classes used and a rough offline crack estimate. Not a breach check.
- Copy the output of Password Strength if you need it elsewhere. Size/complexity still follows: Entropy from charset pool × length. Crack time assumes 1e10 guesses/s. Not a leak lookup.
- If the text job is actually Create one or many random passwords on this device., leave Password Strength and open Password Generator.
When not to use Password Strength
Skip Password Strength when a neighbor tool matches better — start with Password Generator or HMAC-SHA256 — or when the description already warns the job will fail. In the tool’s own words: Charset-pool entropy only. Shows classes used and a rough offline crack estimate. Not a breach check.
Questions about Password Strength
- What does Password Strength do that other Crypto pages on this site do not?
- Charset-pool entropy only. Shows classes used and a rough offline crack estimate. Not a breach check. Short version: Estimate password entropy and crack time.
- Does Password Strength upload my file or text to Tool-You servers?
- No. Password Strength runs in this browser tab. Files stay on the device. Limit note: Entropy from charset pool × length. Crack time assumes 1e10 guesses/s. Not a leak lookup.
- Should I use Password Generator instead of Password Strength?
- Use Password Strength when you need Estimate password entropy and crack time. Use Password Generator when you need Create one or many random passwords on this device. They share a category (Crypto) but not the same job.
- What are the limits of Password Strength?
- Entropy from charset pool × length. Crack time assumes 1e10 guesses/s. Not a leak lookup. Also: Charset-pool entropy only. Shows classes used and a rough offline crack estimate. Not a breach check.