PBKDF2 Hash Generator Online (SHA-256)

Derive a PBKDF2-HMAC-SHA256 key from a password: adjustable number of iterations, automatic salt, in your browser.

Long-standing standard (RFC 8018), widely supported. Uses little memory, so it needs many iterations.

Hash (format to store)

—

Verify a password
Encoded hash
Password to test
Enter a hash and a password.

100% local processing, nothing is uploaded

How does it work?

PBKDF2 (RFC 8018) derives a key from a password by repeating an HMAC function a large number of times. Unlike Argon2 or scrypt, it uses little memory: its only defense is the number of iterations, which therefore needs to be high.

This tool uses PBKDF2-HMAC-SHA256. The encoded hash contains the number of iterations and the salt. The computation runs in a worker.

Examples

OWASP recommendation

At least 600,000 iterations for SHA-256 (OWASP recommendation). The hash starts with $pbkdf2-sha256$i=600000$….

Supported everywhere

PBKDF2 is available natively in browsers (SubtleCrypto) and most platforms, which explains its persistence despite more modern functions such as Argon2.

Frequently asked questions

Why does the computation take several seconds?
That is intentional. These functions are designed to be slow and resource-hungry, so that an attacker who stole the database can only test very few passwords per second. The computation runs in a worker: the page stays responsive.
Is PBKDF2 still recommended?
It remains acceptable with a high number of iterations and is sometimes required by standards (FIPS). But against an attacker equipped with GPUs, memory-hard Argon2id or scrypt offer better protection.
Is my data sent anywhere?
No. All the computation happens in your browser, in JavaScript and WebAssembly. Your text, your files and your hashes never leave your device: no network request is made during hashing, and nothing is stored on a server.