Token Strength Estimator
Estimate the entropy of an API key, session token or UUID, excluding fixed vendor prefixes, with recognised formats scored by their real random portion and guess times at realistic attack rates.
Last reviewed by the Radiatus Cloud team
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
Token strength is a different question from password strength
A password is chosen by a person, so measuring it means guessing how predictable that choice was: dictionary words, substitutions, keyboard patterns. A token is generated by a machine, so if it came from a proper random number generator its strength is simply its length times the log of its alphabet, and no pattern analysis is needed or useful. That makes the calculation exact and the assumption everything. This tool states the assumption plainly rather than presenting an upper bound as though it were a measurement.
Fixed prefixes carry no entropy
Modern credentials advertise what they are: a GitHub token starts ghp_, a Stripe secret key sk_live_, an AWS access key AKIA. Those prefixes exist so that leaked credentials can be detected by scanning, and they are identical in every token of that type. A strength meter that counts the whole string therefore overstates every prefixed token, sometimes by twenty bits or more. This tool identifies the prefix, excludes it, and says how much it would have added if counted.
The alphabet is an assumption, so assume downward
A token is a string of characters, and how much entropy each character carries depends on the alphabet the generator drew from. That is not visible in the output: a thirty-two character string of hex digits looks identical whether it came from a hex generator or from a base62 generator that happened to avoid the other characters. This tool assumes the smallest alphabet that could have produced what it can see, which can only understate strength. Assuming a wider one would overstate it, and a security tool that errs optimistically is worse than one that errs the other way. Override it when you know the generator.
Length is rarely what actually protects a token
The time-to-guess figures assume an attacker can test candidates at the stated rate, and for a remote API that rate is set by the service rather than by arithmetic. A sixty-bit token behind strict rate limiting can outlast a hundred-and-twenty-eight-bit one that was committed to a public repository. Entropy is a floor worth clearing, not the thing that usually fails: most credential compromises are disclosures, not guesses.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
How many bits of entropy does a token need?
NIST SP 800-63B treats 112 bits as the floor for secrets protecting long-lived data, and 128 bits is the usual target for anything that cannot be rotated quickly. A 22-character base64url token reaches 132 bits.
Why does a version 4 UUID have 122 bits and not 128?
Six of its 128 bits are fixed by the specification: four carry the version and two the variant. Only 122 are random, which is why counting the characters of the string gives the wrong answer.
Does a prefix like ghp_ or sk_live_ add strength?
No. It is identical in every token of that type, so it contributes exactly zero entropy. This tool excludes it from the count and reports how much a meter that included it would have overstated.
Is this a measurement of my token entropy?
No. It is an estimate under two stated assumptions: that a cryptographic generator produced the token, and that it drew from the smallest alphabet consistent with the characters visible. Nothing in a string can reveal whether a weak generator made it, so a poor source looks identical to a good one.
Why does a JWT get no entropy score?
Because a JWT is not a random secret. Its header and payload are readable base64url-encoded JSON that anyone holding the token can decode without a key. Its security rests on the signature being unforgeable, so a length-times-alphabet figure would be meaningless and reassuringly large.
What about UUID versions other than 4?
Version 1 and 6 are built from a timestamp and the network card address, version 7 begins with a millisecond timestamp, and versions 3 and 5 are hashes of a name. None is a random secret, so the tool explains that rather than reporting a figure. Only version 4 is random, at 122 bits.
Why does my base62 token score as hexadecimal?
Because every character in it happens to be a hex digit, and the smallest alphabet consistent with that is 16. The alphabet belongs to the generator and is not visible in one sample, so the tool assumes downward rather than overstating. Set the alphabet explicitly to get the real figure.
Is my token sent anywhere?
No. The analysis runs entirely as JavaScript in this page and nothing is transmitted, which is the only basis on which pasting a real credential into a web page could be reasonable.
Why do the guess times assume half the keyspace?
Because for a uniformly random secret an attacker expects to find it halfway through an exhaustive search. Quoting the full keyspace would overstate the time by a factor of two.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Paste a token to analyse it.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.