Password Hash Generator

Derive a PBKDF2 password hash in the browser with a random salt, an iteration count you control, and a self-describing string for your database.

A password hash has to be slow and salted, which is why password storage uses a key derivation function rather than a plain hash. This tool derives PBKDF2 with the Web Crypto API, the algorithm available in a browser, and writes the result in a self-describing string.

Output

                

Paste or type something above.

Questions about password hash generator

Is PBKDF2 the best password hash?
Argon2id and bcrypt are stronger choices when your server supports them. PBKDF2 is what the browser can do without a server, so treat this as a development and migration aid.
Why is there an iteration count?
It makes each guess expensive. A higher count slows attackers down and slows you down a little at login, which is the trade-off you tune over time.
Do I need to store the salt separately?
No. The salt is inside the output string, so one column holds the algorithm, iterations, salt, and hash together.