Argon2 (Argon2id) Hash Generator Online

Hash a password with Argon2id, the function recommended today: adjustable memory and passes, automatic salt, in your browser.

Winner of the Password Hashing Competition (2015), recommended today. Combines memory hardness and GPU resistance.

Hash (format to store)

—

Verify a password
Encoded hash
Password to test
Enter a hash and a password.

100% local processing, nothing is uploaded

How does it work?

Argon2id won the Password Hashing Competition (2015) and is today’s reference recommendation. Three settings: memory (resists GPUs and dedicated hardware), the number of passes (time) and parallelism.

The encoded hash (“$argon2id$v=19$m=…,t=…,p=…”) contains all the parameters and the salt. The computation runs in a worker; in pure JavaScript, high memory settings can take a few seconds.

Examples

A starting configuration

64 MiB of memory, 3 passes, 1 lane: a good starting point according to OWASP. The hash starts with $argon2id$v=19$m=65536,t=3,p=1$… (65,536 KiB = 64 MiB).

Memory cost

Doubling the memory (from 64 to 128 MiB) roughly doubles the cost for an attacker without slowing down legitimate verification excessively: that is what makes Argon2 so resistant to graphics cards.

Frequently asked questions

Why does the computation take several seconds?
That is intentional. These functions are designed to be slow and resource-hungry, so that an attacker who stole the database can only test very few passwords per second. The computation runs in a worker: the page stays responsive.
Argon2id, Argon2i or Argon2d?
Argon2id is the variant recommended by default: it combines the defenses of Argon2i (against side-channel attacks) and Argon2d (against time-memory trade-offs). This tool uses Argon2id.
Is my data sent anywhere?
No. All the computation happens in your browser, in JavaScript and WebAssembly. Your text, your files and your hashes never leave your device: no network request is made during hashing, and nothing is stored on a server.