Skip to content
UniKit

Argon2 hash generator

Generate password hashes with a self-written RFC 9106 Argon2id / Argon2i / Argon2d implementation: tune memory, passes and parallelism, then read the digest as hex, base64 or a PHC string ($argon2id$v=19$m=…) plus the effective memory and timing.

Runs in your browserEvery computation happens in your browser — your data never leaves this device.

Input and parameters

This is a self-written pure-JS Argon2 implementation (64-bit maths done with BigInt). Results match the three official RFC 9106 test vectors, Node’s crypto.argon2Sync and the phc-winner-argon2 command line. Everything runs locally — the password and salt never leave this page.

Salt length ≥ 8 bytes

Result

Set the parameters and press Generate hash. The salt field is pre-filled with the hex of "somesalt" so you can line the result up with the RFC and CLI values.

What this tool does

  • Pick sane hashing parameters: sweep memory, passes and parallelism here, watch how the cost moves, then lock in the settings your server can afford.
  • Reproduce someone else’s result: given a `$argon2id$v=19$m=65536,t=3,p=4$…` string, reuse its salt and parameters to confirm your own implementation or library agrees.
  • Teaching and sanity checks: how “memory hard” is Argon2 really? Bump memory from 8 KiB to 32 KiB and watch the time grow almost linearly — far more convincing than reading the spec.
  • Produce a PHC string (salt and parameters included) that you can paste straight into config or a test fixture without hand-rolling base64.

Example

Input

Password password, salt 736f6d6573616c74 (UTF-8 hex of "somesalt"), variant Argon2id, memory 32 KiB, 3 passes, parallelism 1, 32-byte output

Output

Hex digest 6d4c5fa26a057c23e3a4f72ae34c64e71398c851f2c79464e3e670ed41b543f9; PHC string $argon2id$v=19$m=32,t=3,p=1$c29tZXNhbHQ$bUxfomoFfCPjpPcq40xk5xOYyFHyx5Rk4+Zw7UG1Q/k

These parameters are tiny (32 KiB), so the browser returns instantly. The phc-winner-argon2 CLI prints exactly the same digest for `printf password | argon2 somesalt -id -t 3 -k 32 -p 1 -l 32 -r`.

Frequently asked questions

Is this really Argon2, or another algorithm in disguise?

It really is Argon2. This page reimplements the RFC 9106 building blocks in pure JS — H0 preprocessing, the H' variable-length hash, memory matrix filling, the BlaMka compression function and the index function — and the unit tests compare byte for byte against the three official RFC test vectors (Argon2d / Argon2i / Argon2id with m=32 KiB, t=3, p=4), plus cross-checks against Node’s crypto.argon2Sync and the phc-winner-argon2 CLI. 64-bit maths uses BigInt, which is why it is much slower than a native build.

What parameters should production use?

Start from the official guidance: Argon2id, 64 MiB of memory, 3 passes, parallelism equal to your available cores (4 is common), 32-byte output. Then tune against your own server benchmarks, aiming for 0.3–0.5 s per hash. Remember the pure-JS implementation in the browser is dozens of times slower, so its timing is not a server-side metric.

Argon2id, Argon2i or Argon2d?

Take Argon2id, which is what both the RFC and OWASP recommend. It uses data-independent addressing for the first half of the first pass (cache-timing resistance) and data-dependent addressing afterwards (GPU/ASIC resistance). Argon2i is the most side-channel resistant but the weakest against GPUs; Argon2d is the strongest against GPUs but easier to attack through side channels.

Which matters more, memory or passes?

Raise memory first. Argon2’s memory-hardness means an attacker running many guesses in parallel must provision just as much RAM, which pushes the cost up sharply; passes only add time linearly. The tool rounds memory down to a multiple of 4 × parallelism (the segmentation the spec requires) and the result panel shows the memory that actually took effect.

How long should the salt be, and can I reuse it?

One independent random salt per password, at least 16 bytes (that is what the generate button produces). The salt is not secret — it travels inside the PHC string — but it stops identical passwords from producing identical digests and keeps a single rainbow table from covering every user. Only fill in a fixed salt when reproducing a test vector or someone else’s hash.

Keywords:argon2argon2idpassword hashphc stringkey derivationblake2bArgon2 哈希密码哈希口令哈希内存硬函数密钥派生RFC 9106

Related tools