Home / Security & Crypto Tools / PBKDF2 Generator
Security & Crypto Tools

PBKDF2 Generator

Derive PBKDF2 keys locally with exact salt bytes, HMAC hash, work factor and output length, then verify or export the parameters needed to reproduce the same key.

UTF-8 · hex · Base64 saltreproduce external systems byte-for-byte
SHA-256 · 384 · 512explicit PRF, iterations and dkLen
Expected-key verificationhex, Base64 or Base64URL comparison
Portable parameter auditexports no password or passphrase
—PBKDF2 via Web Crypto

This is a standards-based key-derivation utility, not a recommendation for storing website passwords. Password-storage systems need an application-specific, maintained design and current guidance.

All sensitive values on this page are processed in your browser. Do not treat a browser utility as a replacement for an audited password manager, hardware security device, or application-specific security review.

PBKDF2 interoperability workbench

Derive, verify and audit the exact PBKDF2 byte parameters

Use text, hex, Base64 or Base64URL salt bytes, choose the HMAC hash and work factor, then compare an expected derived key without sending the password anywhere.

Web Crypto · browser-local
—this browser
—PBKDF2 blocks
—conceptual HMAC calls
—password-storage reference
Not requestedexpected-key comparison

Derived key — hex

Derived key — Base64

Salt bytes actually used

Hex—
Base64—

Copyable derivation audit

Portable test bundle (password excluded)

Ready to derive locally.
Security boundary. The OWASP buttons are current password-storage reference points, not a guarantee that PBKDF2 is the right production choice or that browser timing matches your server. OWASP currently prefers modern password-hashing choices such as Argon2id where available and gives PBKDF2 guidance for relevant/FIPS-oriented environments. Preserve the exact salt bytes and parameters for interoperability. The exported bundle intentionally excludes the password. See the OWASP Password Storage Cheat Sheet.

Browser-local cryptographic utilities

preserves the established Web Crypto workflows while connecting token, key, KDF, encryption/signature, fingerprint and verification jobs. Inputs stay in your browser unless the page clearly states that a network request is required.

Protocol boundary

Correct primitive output does not certify a complete protocol, key-management system, parameter choice, endpoint, or production deployment. Match the source system exactly and use established application/security libraries for production authentication and storage.

Search by task, tool name, or category. Press Esc to close.
Start typing to find a tool.