>_devtools

Argon2 Hash Generator & Verifier

Generate and verify Argon2id, Argon2i and Argon2d password hashes with adjustable memory, iterations and parallelism.

What this does

Generates Argon2id, Argon2i or Argon2d password hashes (RFC 9106) in the PHC string format and verifies a password against an existing Argon2 string. You control memory, iterations, parallelism and the hash length, and each field of the result is explained.

The parameters

  • m is memory in KiB. It is the main defence against GPU and ASIC cracking.
  • t is the number of passes over that memory.
  • p is the number of lanes. It changes the output, so verification must use the same value as hashing, even if it runs on one thread.

OWASP's minimum Argon2id settings are 19 MiB with t=2, p=1 (the default here), or 46 MiB with t=1, or 12 MiB with t=3. The inspector flags strings below those. In-browser hashing is several times slower than native, and memory is capped at 256 MiB so a mistyped value cannot exhaust your machine.

Which variant

Argon2id is the right choice for passwords: it is partly data-independent (resists side channels) and partly data-dependent (resists time-memory trade-offs).Argon2i is fully data-independent and Argon2d fully data-dependent, which suits cryptocurrency proof-of-work more than password storage.

Format

The output looks like $argon2id$v=19$m=19456,t=2,p=1$salt$hash, with a random 16-byte salt and unpadded Base64. Other algorithms are in thepassword hash generator.

Privacy

The password stays in your browser, is hashed in a background worker, and is never stored or sent anywhere.