Argon2 Hash Generator & Verifier
Argon2id hashes with OWASP and RFC 9106 settings, made and checked on your device.
Argon2 hash
Use these settings in code
About the Argon2 Hash Generator & Verifier
Argon2 won the Password Hashing Competition in 2015 and is standardised in RFC 9106. It is deliberately slow and memory-hard: every guess an attacker makes costs the same memory and time it costs you, which makes GPU cracking expensive. This tool hashes a password with Argon2id, Argon2i or Argon2d with any memory (m), passes (t), lanes (p), salt and output length, and gives you the standard PHC string ($argon2id$v=19$m=…,t=…,p=…$salt$hash) that libraries store, plus the raw hash in hex and Base64.
One-click presets apply OWASP’s minimum settings and the two RFC 9106 recommendations, and every setting is compared with them. The Verify tab reads a stored hash, explains its parameters and checks a password against it. Hashing runs in WebAssembly in a background worker, so nothing you type leaves your device.
How to use it
- Type the password, choose a preset (OWASP’s minimum, 19 MiB and 2 passes, is selected) or enter your own memory, passes, lanes and output length.
- Press Hash password. The PHC string appears with the time it took on this device; copy it, or open Use these settings in code for Node.js, Python or PHP.
- Under Salt and secret key you can change the length of the random salt (16 bytes by default), add a secret key, or — to reproduce a known hash — tick Use my own salt and enter the salt as text, hex or Base64.
- To check a password, choose Verify, paste the hash, type the password (as text or hex, and the secret key if one was used) and press Verify password.
Examples
Argon2i · password "password" · salt "somesalt" · m=65536 KiB, t=2, p=1 · 32 bytes
$argon2i$v=19$m=65536,t=2,p=1$c29tZXNhbHQ$wWKIMhR9lyDFvRz9YTZweHKfbftvj+qf+YFY4NeBbtA
Tick Use my own salt, type somesalt as text and pick Custom settings to reproduce it.
Argon2id · "hunter2" · secret "pepper" · m=65536, t=2, p=1 · salt (Base64) gZiV/M1gPc22ElAH/Jh1Hw
$argon2id$v=19$m=65536,t=2,p=1$gZiV/M1gPc22ElAH/Jh1Hw$CWOrkoo7oJBQ/iyh7uJ0LO2aLEfrHwTWllSAxT0zRno
The secret is not in the string, so verifying needs it again.
$argon2i$v=19$m=1024,t=2,p=2$YzJBSzV4TUhkMzc3d3laeg$zqU/1IN0/AogfP4cmSJI1vc8lpXRW9/S0sYY2i2jHT0 · password "rasmuslerdorf"
✓ Match — with a warning that 1 MiB and 2 passes are far below today’s minimums
Common uses
- Creating a hash for a seed user or test fixture in an app that stores Argon2 hashes.
- Checking what memory and time settings an existing database uses, and whether they meet OWASP’s minimum.
- Measuring how long a setting takes before choosing parameters for a login server.
- Debugging a login: does this password really produce the stored hash?
Choosing the parameters
The OWASP Password Storage Cheat Sheet says: "Use Argon2id with a minimum configuration of 19 MiB of memory, an iteration count of 2, and 1 degree of parallelism", and lists equal-strength alternatives — 46 MiB with 1 pass, 12 MiB with 3, 9 MiB with 4 and 7 MiB with 5 (the 1- and 2-pass ones are not for Argon2i). RFC 9106 §4 recommends Argon2id with t=1, p=4 and 2 GiB of memory where that is affordable, otherwise t=3, p=4 and 64 MiB, both with a 128-bit salt and a 256-bit tag. Both sources say the same thing in the end: use as much memory and time as your server can afford per login, and measure on that server.
What the PHC string contains
$argon2id$v=19$m=19456,t=2,p=1$<salt>$<hash> holds everything needed to verify: the type, the version (19 = 0x13, the only version in RFC 9106), the memory in KiB, the passes and lanes, the salt and the hash, both in standard Base64 without "=" padding. A secret key (pepper) is never stored in it. The PHC string specification limits salts to 8–48 bytes and outputs to 12–64 bytes for strict parsers; this tool warns when you go outside those limits.
Argon2id, Argon2i or Argon2d?
- Argon2id — the hybrid that RFC 9106 requires every implementation to support and recommends when in doubt. Use it.
- Argon2i — memory access does not depend on the password, which resists side-channel attacks, but it needs more passes to resist GPU attacks.
- Argon2d — the strongest against GPUs, but its memory access depends on the password, which can leak through side channels. RFC 9106 describes it as suitable for cryptocurrencies and proof-of-work, where side-channel timing attacks are not a threat; for passwords, choose Argon2id.
Limitations
- Hashing runs in WebAssembly in a single thread: lanes (p) change the result but not the speed, so a server with several cores is faster than this tool at p > 1.
- Phones and some browsers cannot allocate very large memory costs (the 2 GiB RFC 9106 option in particular); the tool reports an out-of-memory error instead.
- Associated data (Argon2’s optional “X” input,
data=in PHC strings) and the old version 1.0 (v=16) are not supported. - Passwords, salts and secrets are never stored or sent; only the chosen parameters are remembered in this browser.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
Why is the hash different every time?
A new random salt (16 bytes unless you change its length) is made for every hash and stored inside the string, so the same password never gives the same hash twice. Verification reads the salt back from the string.
Can an Argon2 hash be decrypted?
No. Argon2 is one-way: the only way back is to guess passwords and hash each guess, which the memory and time cost make slow on purpose. That is why strong, unique passwords still matter.
Which settings should I use?
Start with OWASP’s minimum (Argon2id, 19 MiB, 2 passes, 1 lane) and raise memory as far as your server allows; the RFC 9106 options are stronger if you can afford them. Measure on the server that will verify logins, not only in your browser.
Is Argon2 better than bcrypt?
For new systems, OWASP recommends Argon2id first, then scrypt, and bcrypt only for legacy systems where those are not available. Argon2 also has no 72-byte password limit. Existing bcrypt hashes with a cost of 10 or more are still acceptable.
What is the secret key (pepper)?
An optional secret value K that RFC 9106 mixes into the hash. Kept outside the database (in a vault or configuration), it means a stolen database alone is not enough to test guesses. It is not in the PHC string, so losing it makes every hash unverifiable — and not every library supports it.
Is it safe to type a real password here?
Hashing happens in your browser and nothing is sent or stored. Still, avoid pasting live production passwords into any website you do not need to — test passwords are enough to try settings.