Algorithms

scrypt

A memory-hard password KDF. Needs a salt and prints the one it drew and the cost it ran with
IDscrypt23 / 24password · variable
Hash / Password

scrypt

Slow on purpose and hungry for memory.

Digest
keyLength you pick
HMAC
no key mode
Security
Memory-hard KDF
Family
2 in password
6 options, 0 required

Sample

hex
ed5d2331215614c585c85ca3c8a3dd98d5563557de457d720238db74dd3e0793a2964fcbdceb457b99456966c06f2b10a20404739ffa3a3d627705ab059a6338
base64
7V0jMSFWFMWFyFyjyKPdmNVWNVfeRX1yAjjbdN0+B5Oilk/L3OtFe5lFaWbAbysQogQEc5/6Oj1idwWrBZpjOA==

Options

encodingstring
default hex
Output encoding: hex, base64, base64url, binary
saltstring
optional
Salt in hex; 32 random bytes when omitted
Nnumber
default 16384
CPU/memory cost (power of 2)
rnumber
default 8
Block size
pnumber
default 1
Parallelization
keyLengthnumber
default 64
Output key length in bytes

Access

Createcreate("scrypt")
CLIhashes scrypt 'hello world' --salt 73616c74 --N 1024
Tryplayground with the sample above
Kinpbkdf2

scrypt fills a big block of memory and reads it back in an order that depends on the data. That makes it expensive on GPUs and ASICs, which is the whole reason it exists. Litecoin mines with it, and wallets from Ethereum's keystore to BIP38 derive keys with it.

ts
create("scrypt").hash("password", { salt: "4e61436c", N: 1024, r: 8, p: 16 }).digest;
// "fdbabe1c9d3472007856e7190d01e9fe7c6ad7cbc8237830e77376634b3731622eaf30d92e22a3886ff109279d9830dac727afb94a83ee6d8360cbdfa2cc0640"

That's the second test vector of RFC 7914: NaCl as salt, in hex here, because the salt is hex by default. Without a salt, 32 random bytes are drawn and reported in result.options. Keep them, Salted KDFs has the full story.

Memory is 128·r·N bytes, 16 MiB at the defaults. The page above computes its sample at N 1024, so the tab doesn't freeze while it renders.