Password Hash Generator
Derive a PBKDF2 password hash in the browser with a random salt, an iteration count you control, and a self-describing string for your database.
How to use
- Type the password.
- Set the iteration count, and keep the generated salt unless you have a reason to supply your own.
- Copy the hash and store the parameters with it.
A password hash has to be slow and salted, which is why password storage uses a key derivation function rather than a plain hash. This tool derives PBKDF2 with the Web Crypto API, the algorithm available in a browser, and writes the result in a self-describing string.
Paste or type something above.
Questions about password hash generator
- Is PBKDF2 the best password hash?
- Argon2id and bcrypt are stronger choices when your server supports them. PBKDF2 is what the browser can do without a server, so treat this as a development and migration aid.
- Why is there an iteration count?
- It makes each guess expensive. A higher count slows attackers down and slows you down a little at login, which is the trade-off you tune over time.
- Do I need to store the salt separately?
- No. The salt is inside the output string, so one column holds the algorithm, iterations, salt, and hash together.
Related tools
- Hash Generator Hash text with MD5, SHA-1, SHA-256, SHA-384, or SHA-512, compare the digests side by side,...
- JWT Secret Generator Create random signing secrets for JSON Web Tokens with a length, alphabet, and batch size...
- UUID Generator Generate random UUID v4 or time-ordered UUID v7 values in bulk, with optional uppercase, b...