PBKDF2 key derivation
Derive keys from a password and salt with WebCrypto PBKDF2 — SHA-1 / SHA-256 / SHA-512, custom iteration count and key length, hex / Base64 output plus security advice.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
Everything runs locally with WebCrypto; the password and salt never leave your device.
Fill in the password and salt, then press “Derive key”
What this tool does
- Derive an encryption key from a passphrase: enter the password and salt, choose the hash, iteration count and key length, and get the key bytes as hex or Base64 for symmetric encryption such as AES.
- Cross-check a backend implementation: PBKDF2 is a standard algorithm (RFC 8018), so deriving the same password, salt, iterations, hash and length locally confirms the server uses the same parameters.
- Judge parameter strength: the tool follows the OWASP 2023 guidance, telling you plainly when fewer than 100,000 iterations make brute force cheap, or when the salt is shorter than 16 bytes.
- Generate a random salt on the spot: press Random salt to draw a cryptographically random salt of the chosen byte length, in hex or Base64 encoding.
Example
Input
Password: password Salt: salt (UTF-8 text) Hash: SHA-256 Iterations: 1000 Key length: 16 bytes
Output
Hex: 632c2812e46d4604102ba7618e9d6d7d Base64: YywoEuRtRgQQK6dhjp1tfQ== Security advice: weak parameters — iteration count too low, salt too short
"salt" is exactly 4 bytes in UTF-8, which is also the minimum accepted salt length. 1000 is the lowest allowed iteration count; for production, follow the advice and raise it above 600,000.
Frequently asked questions
How is PBKDF2 different from just hashing with SHA-256?
A plain hash is far too fast — a GPU tries billions of guesses per second — whereas PBKDF2 deliberately slows every attempt through many iterations and uses a random salt to defeat precomputed rainbow tables. The two outputs are not interchangeable either: you must reuse the exact iteration count and salt to reproduce a PBKDF2 result.
How many iterations should I use?
The tool accepts 1000 upwards, but that is only an engineering floor. OWASP 2023 recommends at least 600,000 for PBKDF2-HMAC-SHA256, and SHA-512 can use fewer. More iterations are safer and slower, and the page shows the measured time per derivation so you can weigh the trade-off.
Why must the salt be unique per password?
The salt makes identical passwords hash differently, which prevents two users with the same password from sharing a hash and stops attackers from cracking in bulk with precomputed tables. Use at least 16 random bytes and never a fixed constant salt.
What key length should I pick?
It depends on the consumer: 16 bytes for AES-128, 24 for AES-192 and 32 for AES-256. The tool allows 1–1024 bytes, but matching the algorithm is enough — a longer key does not strengthen a weak passphrase, since the passphrase entropy is the ceiling.
Are the password and salt uploaded?
No. Derivation uses the built-in WebCrypto API (crypto.subtle.deriveBits) and runs entirely locally, with no network requests, so the password and salt never leave your device.
Keywords:pbkdf2密钥派生key derivationkdf密码哈希salt盐webcrypto迭代次数sha256