Tooleux

Derive a cryptographic key from a password using PBKDF2.

Runs in your browser. Nothing leaves your device.
Derive a key from a password with PBKDF2. Free, offline, runs entirely in your browser. Read more Show less

What is PBKDF2?

PBKDF2 (Password-Based Key Derivation Function 2) is defined in RFC 8018. It applies a hash function like SHA-256 many times to a password and salt, producing a cryptographic key. The iteration count makes each guess expensive, which slows down offline brute-force attacks.

PBKDF2 is used in Wi-Fi WPA2, disk encryption, password managers, and TLS. It is not the strongest KDF available today -" Argon2 is preferred for new designs -" but PBKDF2 is still widely supported and adequate with a high iteration count.

How to use

Enter the password in the input. Provide a salt (random, at least 16 bytes, unique per password). Choose the hash, iteration count, and output length. The result is the derived key in hex or Base64.

For typical use, aim for 100,000+ iterations of SHA-256. Higher iteration counts are slower but stronger.

FAQ

Is my password sent anywhere?

No. Derivation runs entirely in your browser using the Web Crypto API.

What iteration count should I use?

OWASP recommends 600,000 for PBKDF2-HMAC-SHA256 and 210,000 for PBKDF2-HMAC-SHA512 as of 2023. Higher counts are better if performance allows.

PBKDF2 vs Argon2

Argon2 is memory-hard, meaning attackers need large amounts of RAM per guess. PBKDF2 is only CPU-hard. For new systems, prefer Argon2. Use PBKDF2 for compatibility with existing standards.

Should salt be random?

Yes. Each stored password needs a unique random salt. Use a random-bytes generator, not a username or email.

Loads a test value into the form
Password
Derived key