Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Argon2 Hash Generator & Verifier

Argon2id hashes with OWASP and RFC 9106 settings, made and checked on your device.

Security No upload Works offline Free, no sign-up

Hash a password

Type

    Salt and secret key

    A new random salt of this length is made for every hash. RFC 9106 recommends 16 bytes for passwords; PHC strings allow 8–48.

    Argon2’s secret value K (RFC 9106), kept outside the database. It is not part of the hash string, so the same secret is needed to verify.

    Next steps

    About the Argon2 Hash Generator & Verifier

    Argon2 won the Password Hashing Competition in 2015 and is standardised in RFC 9106. It is deliberately slow and memory-hard: every guess an attacker makes costs the same memory and time it costs you, which makes GPU cracking expensive. This tool hashes a password with Argon2id, Argon2i or Argon2d with any memory (m), passes (t), lanes (p), salt and output length, and gives you the standard PHC string ($argon2id$v=19$m=…,t=…,p=…$salt$hash) that libraries store, plus the raw hash in hex and Base64.

    One-click presets apply OWASP’s minimum settings and the two RFC 9106 recommendations, and every setting is compared with them. The Verify tab reads a stored hash, explains its parameters and checks a password against it. Hashing runs in WebAssembly in a background worker, so nothing you type leaves your device.

    How to use it

    1. Type the password, choose a preset (OWASP’s minimum, 19 MiB and 2 passes, is selected) or enter your own memory, passes, lanes and output length.
    2. Press Hash password. The PHC string appears with the time it took on this device; copy it, or open Use these settings in code for Node.js, Python or PHP.
    3. Under Salt and secret key you can change the length of the random salt (16 bytes by default), add a secret key, or — to reproduce a known hash — tick Use my own salt and enter the salt as text, hex or Base64.
    4. To check a password, choose Verify, paste the hash, type the password (as text or hex, and the secret key if one was used) and press Verify password.

    Examples

    The reference implementation’s test vector
    Input
    Argon2i · password "password" · salt "somesalt" · m=65536 KiB, t=2, p=1 · 32 bytes
    Result
    $argon2i$v=19$m=65536,t=2,p=1$c29tZXNhbHQ$wWKIMhR9lyDFvRz9YTZweHKfbftvj+qf+YFY4NeBbtA

    Tick Use my own salt, type somesalt as text and pick Custom settings to reproduce it.

    The PHC string specification example (with a secret key)
    Input
    Argon2id · "hunter2" · secret "pepper" · m=65536, t=2, p=1 · salt (Base64) gZiV/M1gPc22ElAH/Jh1Hw
    Result
    $argon2id$v=19$m=65536,t=2,p=1$gZiV/M1gPc22ElAH/Jh1Hw$CWOrkoo7oJBQ/iyh7uJ0LO2aLEfrHwTWllSAxT0zRno

    The secret is not in the string, so verifying needs it again.

    A hash from PHP’s manual
    Input
    $argon2i$v=19$m=1024,t=2,p=2$YzJBSzV4TUhkMzc3d3laeg$zqU/1IN0/AogfP4cmSJI1vc8lpXRW9/S0sYY2i2jHT0 · password "rasmuslerdorf"
    Result
    ✓ Match — with a warning that 1 MiB and 2 passes are far below today’s minimums

    Common uses

    • Creating a hash for a seed user or test fixture in an app that stores Argon2 hashes.
    • Checking what memory and time settings an existing database uses, and whether they meet OWASP’s minimum.
    • Measuring how long a setting takes before choosing parameters for a login server.
    • Debugging a login: does this password really produce the stored hash?

    Choosing the parameters

    The OWASP Password Storage Cheat Sheet says: "Use Argon2id with a minimum configuration of 19 MiB of memory, an iteration count of 2, and 1 degree of parallelism", and lists equal-strength alternatives — 46 MiB with 1 pass, 12 MiB with 3, 9 MiB with 4 and 7 MiB with 5 (the 1- and 2-pass ones are not for Argon2i). RFC 9106 §4 recommends Argon2id with t=1, p=4 and 2 GiB of memory where that is affordable, otherwise t=3, p=4 and 64 MiB, both with a 128-bit salt and a 256-bit tag. Both sources say the same thing in the end: use as much memory and time as your server can afford per login, and measure on that server.

    What the PHC string contains

    $argon2id$v=19$m=19456,t=2,p=1$<salt>$<hash> holds everything needed to verify: the type, the version (19 = 0x13, the only version in RFC 9106), the memory in KiB, the passes and lanes, the salt and the hash, both in standard Base64 without "=" padding. A secret key (pepper) is never stored in it. The PHC string specification limits salts to 8–48 bytes and outputs to 12–64 bytes for strict parsers; this tool warns when you go outside those limits.

    Argon2id, Argon2i or Argon2d?

    • Argon2id — the hybrid that RFC 9106 requires every implementation to support and recommends when in doubt. Use it.
    • Argon2i — memory access does not depend on the password, which resists side-channel attacks, but it needs more passes to resist GPU attacks.
    • Argon2d — the strongest against GPUs, but its memory access depends on the password, which can leak through side channels. RFC 9106 describes it as suitable for cryptocurrencies and proof-of-work, where side-channel timing attacks are not a threat; for passwords, choose Argon2id.

    Limitations

    • Hashing runs in WebAssembly in a single thread: lanes (p) change the result but not the speed, so a server with several cores is faster than this tool at p > 1.
    • Phones and some browsers cannot allocate very large memory costs (the 2 GiB RFC 9106 option in particular); the tool reports an out-of-memory error instead.
    • Associated data (Argon2’s optional “X” input, data= in PHC strings) and the old version 1.0 (v=16) are not supported.
    • Passwords, salts and secrets are never stored or sent; only the chosen parameters are remembered in this browser.

    Privacy

    Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.

    Frequently asked questions

    Why is the hash different every time?

    A new random salt (16 bytes unless you change its length) is made for every hash and stored inside the string, so the same password never gives the same hash twice. Verification reads the salt back from the string.

    Can an Argon2 hash be decrypted?

    No. Argon2 is one-way: the only way back is to guess passwords and hash each guess, which the memory and time cost make slow on purpose. That is why strong, unique passwords still matter.

    Which settings should I use?

    Start with OWASP’s minimum (Argon2id, 19 MiB, 2 passes, 1 lane) and raise memory as far as your server allows; the RFC 9106 options are stronger if you can afford them. Measure on the server that will verify logins, not only in your browser.

    Is Argon2 better than bcrypt?

    For new systems, OWASP recommends Argon2id first, then scrypt, and bcrypt only for legacy systems where those are not available. Argon2 also has no 72-byte password limit. Existing bcrypt hashes with a cost of 10 or more are still acceptable.

    What is the secret key (pepper)?

    An optional secret value K that RFC 9106 mixes into the hash. Kept outside the database (in a vault or configuration), it means a stolen database alone is not enough to test guesses. It is not in the PHC string, so losing it makes every hash unverifiable — and not every library supports it.

    Is it safe to type a real password here?

    Hashing happens in your browser and nothing is sent or stored. Still, avoid pasting live production passwords into any website you do not need to — test passwords are enough to try settings.

    Quick answers and tool search

    Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.