PBKDF2 Hash Generator Online (SHA-256)
Derive a PBKDF2-HMAC-SHA256 key from a password: adjustable number of iterations, automatic salt, in your browser.
Long-standing standard (RFC 8018), widely supported. Uses little memory, so it needs many iterations.
Hash (format to store)
—
Verify a password
100% local processing, nothing is uploaded
How does it work?
PBKDF2 (RFC 8018) derives a key from a password by repeating an HMAC function a large number of times. Unlike Argon2 or scrypt, it uses little memory: its only defense is the number of iterations, which therefore needs to be high.
This tool uses PBKDF2-HMAC-SHA256. The encoded hash contains the number of iterations and the salt. The computation runs in a worker.
Examples
OWASP recommendation
At least 600,000 iterations for SHA-256 (OWASP recommendation). The hash starts with $pbkdf2-sha256$i=600000$….
Supported everywhere
PBKDF2 is available natively in browsers (SubtleCrypto) and most platforms, which explains its persistence despite more modern functions such as Argon2.