Output will appear here
Click in the output to select all text
Output will appear here
Click in the output to select all text
Generate and verify Bcrypt password hashes with configurable work factor/cost.
Simulate and inspect modern memory-hard password hashes (Argon2 / Scrypt).
Encrypt or decrypt text with AES-256 using a custom passphrase.
Generate HMAC signatures using SHA-256, SHA-512, SHA-1, or MD5 with a secret key.
Generate strong random passwords or memorable passphrases with a live entropy/strength meter, bulk generation, and ambiguous-character exclusion.
This PBKDF2 tool derives a cryptographic key from a password using a custom salt and iteration count, computed entirely in your browser. PBKDF2 (Password-Based Key Derivation Function 2, defined in RFC 2898) repeatedly applies an HMAC hash function thousands or millions of times to slow down brute-force attacks, which is why it's used inside WPA2 Wi-Fi security, encrypted file formats, and as the key-stretching step before symmetric encryption with a password-derived key. Developers implementing password-based encryption, security engineers auditing iteration counts, and students learning about key stretching will find this tool useful for generating and verifying derived keys. Your password, salt, and all computation stay entirely client-side using the Web Crypto API — nothing is ever transmitted to a server, which matters enormously here since you're working directly with password material. There's no signup and results compute instantly, though higher iteration counts will take proportionally longer by design — that's the whole point of key stretching. If you're hashing passwords for account storage rather than deriving an encryption key, check out this platform's bcrypt or Argon2 tools instead. Scroll down to derive a key now.
PBKDF2 derives a strong cryptographic key from a password, commonly used for encrypting files, securing WPA2 Wi-Fi networks, and as a key-stretching step before symmetric encryption.
It can be, if configured with a high iteration count and used correctly, but modern memory-hard alternatives like Argon2 or bcrypt are generally preferred for storing login passwords since they resist GPU/ASIC cracking better.
Current guidance (OWASP) recommends at least 600,000 iterations for PBKDF2-HMAC-SHA256, though the right number depends on your performance budget and threat model.
A salt ensures that identical passwords produce different derived keys, preventing attackers from using precomputed rainbow tables against multiple accounts at once.
PBKDF2 is CPU-hardening only and configurable purely by iteration count, while bcrypt (and Argon2) add memory-hardness, making them more resistant to parallelized GPU and ASIC cracking attacks.
Yes, PBKDF2 is still approved by NIST and widely used, though Argon2 is generally considered the stronger modern choice when available.
Yes, that's intentional — each iteration adds computational cost, which is exactly what slows down brute-force password-guessing attacks.
How AES Encryption Works (Without the Math)
How AES encryption works in plain English: blocks, rounds, key sizes, and why AES-256-GCM beats CBC. No linear algebra required, just the parts that matter.
HMAC vs Plain Hashing: Why the Key Matters
HMAC vs hash explained: a plain hash proves only that data didn't change, while HMAC's secret key also proves who produced it — integrity versus authenticity.