Turn a password into a cryptographic key with PBKDF2-HMAC-SHA256. Set your own salt, iteration count and key length, then copy the result as hex or Base64. This is the same building block used by Wi-Fi WPA2, encrypted archives and many password managers.
You cannot recover the original input from a hash.
bcrypt or argon2 for passwords; SHA-256 for integrity.
Compare digests for integrity; prefer slow algorithms for secrets.
Turn a password into a cryptographic key with PBKDF2-HMAC-SHA256. Set your own salt, iteration count and key length, then copy the result as hex or Base64. This is the same building block used by Wi-Fi WPA2, encrypted archives and many password managers.
Type the password or passphrase you want to derive a key from.
Use a unique random salt and at least 100,000 iterations for password storage.
Pick a 256-bit (32-byte) key for AES-256, or longer for other uses.
| Setting | Value |
|---|---|
| Hash | HMAC-SHA256 |
| Iterations | 100,000 |
| Key length | 256 bits (32 bytes) |
| Salt | 16 random bytes |
Use the same salt and iterations later to derive the identical key again.
It is completely free, private and requires no signup.
Use the tool nowPassword-Based Key Derivation Function 2 (RFC 8018) applies a hash many times with a salt to slow down brute-force attacks and turn a password into a fixed-length key.
At least 100,000 for PBKDF2-HMAC-SHA256 today, and more as hardware gets faster. Aim for a few hundred milliseconds per derivation.
bcrypt and argon2 are usually preferred for storing passwords. PBKDF2 remains the safe, widely-implemented standard and is great for deriving encryption keys.
No. The salt must be unique and random, but it can be stored alongside the hash. Its job is to defeat precomputed tables.
Explore the whole collection — no signup, 100% free & private.