Scrypt Hash Generator Online

Hash a password with memory-hard scrypt: adjustable N, r and p parameters, automatic salt, right in your browser.

Memory-hard, which hinders attacks using specialized hardware.

Hash (format to store)

—

Verify a password
Encoded hash
Password to test
Enter a hash and a password.

100% local processing, nothing is uploaded

How does it work?

scrypt (RFC 7914) is a memory-hard key derivation function, which hinders attacks using specialized hardware. Three parameters: the cost N (a power of two), the block size r and the parallelism p.

The encoded hash (“$scrypt$ln=…,r=…,p=…”) contains the parameters and the salt. The computation runs locally, in a worker.

Examples

Usual parameters

N = 2^15 (32,768), r = 8, p = 1: a common setting. The hash starts with $scrypt$ln=15,r=8,p=1$…, where “ln” is the base-2 logarithm of N.

Memory used

The memory needed is about 128 × N × r bytes, or ~32 MiB for N = 2^15 and r = 8. Raising N by one step doubles that memory.

Frequently asked questions

Why does the computation take several seconds?
That is intentional. These functions are designed to be slow and resource-hungry, so that an attacker who stole the database can only test very few passwords per second. The computation runs in a worker: the page stays responsive.
scrypt or Argon2?
Both are memory-hard. Argon2id is more recent and generally recommended as the first choice; scrypt remains solid and very widespread, notably in some cryptocurrencies.
Is my data sent anywhere?
No. All the computation happens in your browser, in JavaScript and WebAssembly. Your text, your files and your hashes never leave your device: no network request is made during hashing, and nothing is stored on a server.