PBKDF2 Key Derivation
Derive a key from a password using PBKDF2 (RFC 2898) with Web Crypto API. Free, private, and 100% client-side.
Local only
Recent history
No history yet
How to use
- Enter the password.
- Provide a salt.
- Set iterations (min 100,000) and key length.
- Select the hash algorithm.
- Copy the derived key.
Frequently asked questions
- How many iterations should I use?
- At least 100,000 for general use. OWASP recommends 600,000 for PBKDF2-SHA256 as of 2023.
- What is a salt?
- A salt is random data added to the password before derivation to prevent rainbow table attacks. Use a unique salt per password.
Related tools
scrypt Key Derivation Derive a key from a password using scrypt (memory-hard KDF). Free, private, and 100% client-side. bcrypt Hash Hash passwords with bcrypt or verify bcrypt hashes. Free, private, and 100% client-side. HMAC Generator Generate HMAC (Keyed-Hash Message Authentication Code) with SHA-1/256/512. Free, private, and 100% client-side.