Tooleux

Check whether a plaintext password matches a stored scrypt hash.

Runs in your browser. Nothing leaves your device.
Verify a password against an scrypt hash in your browser. Confirm that a plaintext matches a stored scrypt hash. Free, offline, runs client-side. Read more Show less

What is scrypt verify?

scrypt verify takes a plaintext password and an scrypt hash, re-derives the hash using the parameters embedded in the stored value, and checks whether the two match. It is the check every login system performs when it uses scrypt to protect passwords.

scrypt is a memory-hard password hashing function designed by Colin Percival in 2009. It is one of the three modern password hashing algorithms (alongside bcrypt and Argon2) recommended by OWASP and NIST.

How to verify

Paste the scrypt hash and type the password you want to check. The result is Match or No match.

The hash must include the parameters and salt so the tool can re-derive without extra input. This tool accepts the standard PHC-style format:

$scrypt$ln=15,r=8,p=1$<salt-base64>$<hash-base64>

The three parameters are:

ln - the base-2 logarithm of N (the CPU/memory cost). ln=15 means N=32768. Typical values: 14-18.

r - block size. Typical value: 8.

p - parallelism. Typical value: 1-4.

Alternative format

If your hash does not start with $scrypt$, it may have been produced with a different wrapper. Two fallbacks are supported by the "advanced" section of the settings panel: you can paste the parameters manually, along with the salt and hash separately.

FAQ

Why does verification take 100-500 milliseconds?

scrypt is designed to use a lot of memory and CPU. That is what makes it resistant to GPU cracking attacks. The cost is a small amount of latency each time a password is verified.

What does ln=15,r=8,p=1 mean?

It means N = 2^15 = 32768 iterations of the core mixing function, with a block size of 8 (128 bytes ? 8 = 1KB per iteration), using 1 parallel lane. Total memory needed is roughly 128 ? r ? N bytes = 32 MB.

Is scrypt better than bcrypt?

They are comparable. scrypt is memory-hard, which makes it harder to crack with specialized hardware. bcrypt is more widely deployed. Argon2 is the newest and is the current recommendation from the Password Hashing Competition. All three are adequate; do not switch from one to another without a reason.

Can I verify an Argon2 or bcrypt hash here?

No - each algorithm has its own page. Use the Argon2 Verify or Bcrypt Verify tools.

My hash does not start with $scrypt$

Common formats include Python's base64 output, passlib's variant, and raw hex. If your hash is just the raw derived key, you need to know the parameters separately - the settings panel's advanced section lets you enter them.

Is scrypt reversible?

No. Like every password hash, scrypt is one-way. You can only check whether a candidate matches, never recover the original.

Command line equivalent
# Node with scrypt-js
npm i scrypt-js
node -e '
const { scrypt, scryptSync } = require("scrypt-js");
const N = 32768, r = 8, p = 1;
const password = Buffer.from("hunter2");
const salt = Buffer.from("...", "base64");
const dkLen = 32;
scrypt(password, salt, N, r, p, dkLen).then(dk => {
  console.log(Buffer.from(dk).toString("base64"));
});
'

# Python with hashlib (stdlib)
python3 -c '
import hashlib, base64
dk = hashlib.scrypt(b"hunter2", salt=b"salt", n=32768, r=8, p=1, dklen=32)
print(base64.b64encode(dk).decode())
'

# OpenSSL 3.2+
openssl kdf -keylen 32 -kdfopt pass:password -kdfopt hexsalt:... -kdfopt n:32768 -kdfopt r:8 -kdfopt p:1 SCRYPT
Loads a test value into the form
Advanced - manual parameters (when the hash is not PHC format)