Tooleux

Derive a cryptographic key from a password using scrypt.

Runs in your browser. Nothing leaves your device.
Derive a key from a password with scrypt. Free, offline, runs entirely in your browser. Read more Show less

What is scrypt?

scrypt is a password-based key derivation function designed by Colin Percival in 2009. Unlike PBKDF2, it is memory-hard: each guess requires a large amount of RAM. This makes it much more expensive for attackers to parallelize on GPUs or dedicated hardware.

scrypt is used by Litecoin, some disk encryption tools, and password managers. It has three tuning parameters: N (cost, must be a power of 2), r (block size), and p (parallelism). Increasing N or r increases memory use.

How to use

Enter the password. Provide a random salt. Choose N, r, and p according to your target hardware. The result is a derived key in hex or Base64.

Typical interactive parameters: N=16384, r=8, p=1. Server-side storage can use higher values. Memory required is roughly 128 ?- N ?- r bytes.

FAQ

Scrypt vs Argon2

Both are memory-hard. Argon2 won the Password Hashing Competition in 2015 and is the modern recommendation. Scrypt is older and still secure.

What parameters should I use?

As of 2023, OWASP suggests minimum N=2^17 (131072), r=8, p=1, or N=2^16, r=8, p=2. Higher is better if your hardware allows.

Is N required to be a power of 2?

Yes. Scrypt's algorithm relies on a power-of-two N for its core indexing. Values that are not powers of 2 are invalid.

Is the derivation done locally?

Yes. hash-wasm runs scrypt in the browser via WebAssembly. Nothing is uploaded.

Loads a test value into the form
Password
Derived key