Password Combination Calculator

Select a password length and character set to calculate the theoretical number of possible passwords. The tool shows total combinations in scientific notation, entropy in bits, search-space size, and an optional brute-force time estimate — all computed in your browser from password rules only, never from a real password.

Password Combination Calculator

Privacy: Do not enter a real password. This calculator only needs rules — length and character types. Calculations run locally in your browser.
Formula N = C^L C = pool size, L = length
Whole number, 1–512

Character Set

Exact length N = C^L Length range N = Σ C^k (k=Lₖₑₙ to Lₖₘₓ)
Common values: 10 (digits), 26 (lowercase), 52 (letters), 62 (alphanumeric), 94 (printable ASCII)
Reduces pool by this amount. E.g. excluding O, 0, I, l (4 chars) → enter 4.
Disclaimer: These figures are theoretical estimates only. Real attacks use dictionaries, leaked credentials, predictable patterns, and hardware acceleration. The estimate here is for uniform exhaustive search at the selected rate — not a prediction of actual hacking time.

Search Space Growth (log scale relative to 4-char baseline)

The Password Combination Formula

When each position in a password can independently hold any character from a pool of C characters, the total number of possible passwords of exact length L is:

N = CL

N = possible passwords, C = character pool size, L = password length

The logic is multiplicative: there are C choices for position 1, C choices for position 2, and so on through position L. Multiply them all and you get C × C × ... (L times) = CL. This is sampling with replacement — the same character can appear more than once.

Worked examples

4-Digit PIN

C = 10, L = 4 N = 10^4 = 10,000 Each ATM PIN has a 1-in-10,000 chance of matching yours.

6-Letter Lowercase

C = 26, L = 6 N = 26^6 = 308,915,776 About 309 million possible strings.

8-char Alphanumeric

C = 62, L = 8 N = 62^8 ≈ 2.18 × 10^14 218 trillion combinations.

12-char Full ASCII

C = 94, L = 12 N = 94^12 ≈ 4.76 × 10^23 476 sextillion combinations.
Assumption: These counts assume every character is chosen independently and uniformly from the stated pool. A human who picks Password1! is not sampling uniformly — the actual difficulty of guessing that password is far lower than CL implies.

Password Entropy Explained

Entropy converts the combination count into bits, which makes very large numbers easier to compare. The formula is:

H = L × log₂(C)

Because N = CL, taking log base 2 gives H = log₂(CL) = L × log₂(C). The result is the same information measured in different units: each bit roughly doubles the search space.

ConfigurationPoolLengthCombinationsEntropy
4-digit PIN10410,00013.29 bits
8-char lowercase2682.09 × 10¹¹37.60 bits
8-char alphanumeric6282.18 × 10¹⁴47.63 bits
12-char alphanumeric62123.23 × 10²¹71.45 bits
16-char full ASCII94163.86 × 10³¹104.94 bits
20-char alphanumeric62207.04 × 10³⁵119.08 bits

Adding a single character multiplies the combination count by C. For a 62-character pool, each extra character gives 62× more candidates. Adding symbols (going from C=62 to C=94) multiplies each length by roughly 1.5×. This is why length often matters more than character complexity: length compounds exponentially while pool size is a multiplicative factor per extra character.

Combinations vs Real-World Security

The formula N = CL counts every possible string that fits the stated rules. That number is a mathematical property of the space, not a guarantee of any individual password's strength.

Why they differ

Real passwords chosen by people follow patterns. Common choices include dictionary words, names, dates, keyboard walks (qwerty, 123456), predictable substitutions (p@ssw0rd), and repeated characters. Because these patterns are known, attackers typically start with the most probable candidates rather than searching the entire space uniformly.

A 10-character password from a 94-character pool has a theoretical search space of 94¹⁰ ≈ 5.4 × 10¹⁹. A weak password from that same pool might appear near the top of a known-passwords list and fall within the first few hundred guesses in a dictionary attack.

What the calculation does tell you

Theoretical search space gives the upper bound on difficulty for an attacker who knows only the rules (length and character set) and must search blindly. If the password is truly random, that bound applies directly. It also lets you compare policies: a policy requiring 16 random characters beats a policy requiring 8 characters with complexity rules, regardless of which looks more complicated.

NIST SP 800-63B guidance (verify current version before citing): Modern password guidance shifts away from mandatory complexity rules toward longer passwords, screening against commonly used or compromised passwords, and supporting multi-factor authentication. A large theoretical search space is not a substitute for randomly generated credentials.

Attack models and what they assume

Attack typeTypical rateAssumption
Online rate-limited10–1,000/sRate limits, lockouts in effect
Offline (bcrypt/Argon2)10³–10⁶/sSlow hash; attacker has the hash
Offline (MD5/SHA1)10¹⁰–10¹²/sFast unsalted hash; GPU clusters
Dictionary attackdependsPrioritizes likely candidates, not uniform search
Credential stuffingvariesReuses leaked username/password pairs

Combinations vs Permutations vs Password Counts

In everyday speech people say "password combinations" when they mean the count of ordered strings. Mathematically, that count is neither a combination nor a permutation in the classical sense — it is a count of Cartesian products.

Repetition allowed (typical)

N = C^L Each of L positions can hold any of C characters, independently.

No repetition allowed

N = C! / (C - L)! Also written P(C,L). Requires L ≤ C.

Math combinations (order ignored)

C(n,r) = n! / (r!(n-r)!) Not used for passwords — order matters.

Entropy (either mode)

H = log₂(N) Take log₂ of whatever count you computed.

Passwords are ordered strings: "abc" and "cba" are two different passwords, not two arrangements of the same combination. So the relevant count is always an ordered one. Without restrictions on repetition, it is CL. With a no-repeat rule it is P(C,L) = C!/(C−L)!. If L > C with no repetition, the count is zero — impossible to fill that many positions with unique characters from a smaller pool.

Length Ranges and Special Rules

Length ranges

Some systems accept passwords of varying length. If you need to count every possible password from length Lₘᵢₙ through Lₘₐₓ, you sum the combinations at each valid length:

N = CLₘᵢₙ + CLₘᵢₙ+1 + … + CLₘₐₓ

For example, passwords from 8 to 12 characters in a 62-character pool:

Length62^LContribution
82.18 × 10¹⁴tiny relative to longer lengths
91.35 × 10¹⁶
108.39 × 10¹⁷
115.20 × 10¹⁹
123.23 × 10²¹dominates the sum
Total≈ 3.28 × 10²¹~1.6% larger than 62¹² alone

Because CL grows so quickly, the longest length in a range almost always dominates. Using only CLₘₐₓ is a common shortcut when a conservative upper estimate is acceptable, but the exact figure requires summing each length.

Excluded characters

Excluding characters reduces C directly. If a 94-character pool excludes 0, O, 1, l, and I (5 characters) to avoid visual ambiguity, the effective pool is 94 − 5 = 89, and N = 89L. Exclusions always reduce the theoretical search space, so they have a small cost in combinatorial strength for a usability benefit.

Required character types

A policy requiring at least one character from each of four categories (upper, lower, digit, symbol) excludes strings that use only some categories. Counting valid strings requires subtracting the invalid ones using inclusion-exclusion. For a password of length L with pool C requiring at least one from each of four non-overlapping categories of sizes c₁, c₂, c₃, c₄:

N𝑣ₐₗ𝑖ₑ = CL − Σ(C−c𝑖)L + Σ(C−c𝑖−cⱼ)L − Σ(C−c𝑖−cⱼ−cₖ)L + (c₄)L

The Advanced tab in the calculator uses the full logarithmic approach for arbitrary pool sizes. For exact counts with required-type constraints at large lengths, the differences are typically small relative to CL.

Passphrase Search Space

A passphrase is a sequence of randomly chosen words. If the word list contains W entries and you select K words with replacement, the number of possible passphrases is WK.

Word list size (W)Words (K)CombinationsEntropy
2,048 (BIP-39)41.76 × 10¹³44 bits
2,04867.38 × 10¹⁹66 bits
7,776 (EFF large)52.82 × 10¹⁹64.6 bits
7,77662.21 × 10²³77.5 bits

A 5-word EFF diceware passphrase (W = 7,776) has about 64.6 bits of entropy, which matches a random 11-character alphanumeric password. Both the word-count and the list size matter, just as character count and pool size do for character-based passwords. The critical word is randomly: a passphrase that is a meaningful sentence the user invented does not carry the full entropy of a randomly generated one from that word list.

Common Calculation Mistakes

MistakeCorrect approach
Using only CLₘₐₓ for a length rangeSum Ck for each k from Lₘᵢₙ to Lₘₐₓ
Assuming "symbols" = 32 alwaysSymbols differ by system; document exactly which characters are included
Using C(n,r) for password countsUse CL (ordered, with replacement) or P(C,L) (no repetition)
Adding category sizes when multiplying is neededPool size = sum of category sizes; then raise to the power L
Treating entropy as guaranteed securityEntropy assumes uniform random generation; human choices reduce effective entropy
Ignoring dictionary attacks in time estimatesBrute-force time assumes uniform random search; real attacks are faster on weak passwords
Floating-point overflow for large valuesUse log-domain arithmetic; display log₁₀(N) and scientific notation

Frequently Asked Questions

It depends entirely on length and the character pool. For a 12-character password drawn from 62 characters (letters and digits), there are 62¹² ≈ 3.23 × 10²¹ possible strings. For a 4-digit PIN there are 10⁴ = 10,000. The calculator above lets you set any combination of these parameters instantly.

Use N = CL, where C is the number of distinct characters available and L is the password length. Count up your character types: lowercase (26) + uppercase (26) + digits (10) = 62. Then raise 62 to the power of your target length. That gives the theoretical count of all distinct strings of that length from that pool.

With digits only (C = 10): 10⁸ = 100,000,000. With lowercase letters only (C = 26): 26⁸ = 208,827,064,576. With letters and digits (C = 62): 62⁸ = 218,340,105,584,896. With all printable ASCII (C = 94): 94⁸ = 6,095,689,385,410,816. The choice of character set makes a very large difference.

With alphanumeric characters (C = 62): 62¹² ≈ 3.23 × 10²¹. With all printable ASCII (C = 94): 94¹² ≈ 4.76 × 10²³. These numbers exceed the estimated number of grains of sand on Earth (≈ 7.5 × 10¹⁸), which is why randomly generated passwords at this length are infeasible to brute-force under most attack models.

N = CL, where N is the number of possible passwords, C is the character pool size, and L is the password length. Each of the L positions can independently hold any of the C characters, so there are C choices per position and C × C × … (L times) = CL total strings. When repetition is not allowed, the formula becomes P(C,L) = C! / (C − L)!.

Password entropy is H = L × log₂(C), measured in bits. It is the base-2 logarithm of the number of possible passwords. A 12-character alphanumeric password has H = 12 × log₂(62) ≈ 12 × 5.954 ≈ 71.45 bits. This figure assumes uniform independent character selection. If the password is human-chosen rather than machine-generated, the effective entropy is lower because human choices follow predictable patterns.

Passwords are ordered strings, so "abc" and "cba" count as two different passwords. The relevant count is an ordered one: CL with repetition allowed, or P(C,L) = C!/(C−L)! without repetition. The mathematical combination formula C(n,r) = n!/(r!(n−r)!) ignores order and does not apply to password counting. When people say "password combinations" they actually mean ordered strings — not combinations in the strict mathematical sense.

Yes, because you never enter a real password here. The calculator works from rules only — length and character types — and performs all arithmetic locally in your browser. Nothing is sent to a server. There is no input field for an actual password value, and the results depend only on the rules you select, not on any secret.

Without repetition the count is P(C,L) = C! / (C−L)!, which is always smaller than CL. If L > C, no valid password exists and the count is zero — you cannot fill more positions than there are unique characters. For example, a 7-character password from a 62-character pool without repetition gives 62 × 61 × 60 × 59 × 58 × 57 × 56 ≈ 3.26 × 10¹². The Advanced tab in the calculator handles this mode.

Adding symbols expands the pool from 62 to 94 characters, which multiplies the combination count by roughly 1.5 per character position. That helps theoretically. For randomly generated passwords, adding one extra character of any type has a larger effect than switching to a bigger pool, because each extra position multiplies the search space by the full pool size. For human-chosen passwords, predictable substitutions like @ for a or 3 for e offer little real protection against dictionary attacks that already include these patterns.

Average exhaustive-search time: Tavg = N / (2R), where R is the guess rate in attempts per second. Worst case: Tworst = N / R. For example, 3.23 × 10²¹ candidates at 10⁹ guesses per second gives Tavg ≈ 1.6 × 10¹² seconds ≈ 51,000 years. These figures apply only to uniform exhaustive search. Real attacks against predictable or reused passwords are far faster.

The search space is the set of all candidate strings an attacker would need to consider under a given attack model. It is determined by the assumed length range, character pool, and any known constraints. For an attacker who knows only that a password is exactly 12 characters from a 62-character pool, the search space is 62¹² ≈ 3.23 × 10²¹. If the attacker also knows the password is a dictionary word with a number appended, the effective search space is far smaller.

When passwords can vary in length from Lmin to Lmax, the total count is the sum: CLmin + CLmin+1 + … + CLmax. Because each term is C times larger than the previous one, the longest-length term dominates almost entirely. For a 62-character pool from length 8 to 12, the total is ≈ 3.28 × 10²¹ — only about 1.6% larger than 62¹² alone. The Advanced tab calculates this correctly using the full summation.

A standard 4-digit PIN uses digits 0–9 (C = 10) with repetition allowed, giving 10⁴ = 10,000 possible combinations. If PINs cannot start with 0 the count drops to 9 × 10³ = 9,000. A 6-digit PIN gives 10⁶ = 1,000,000 combinations. These counts assume each digit is chosen independently — real users disproportionately choose PINs like 1234, 0000, and birth years, so practical guessing difficulty is much lower than 10,000 implies.

Key Takeaways

  • The number of possible passwords is N = CL when repetition is allowed, where C is the pool size and L is the length.
  • Password length increases search space exponentially. Adding one character multiplies the count by C.
  • Pool size also matters: going from 62 to 94 characters multiplies each-length count by about 1.5 per character position.
  • No-repeat passwords use P(C,L) = C!/(C−L)!, which requires L ≤ C.
  • Length ranges require summing Ck for each valid length k.
  • Entropy in bits: H = L × log₂(C). It assumes uniform random generation.
  • Theoretical combinations ≠ real-world password strength. Human patterns and reuse dramatically reduce effective security.
  • Never enter an actual password into a search-space calculator. The math only requires rules, not values.