Cryptography
PBKDF2 Key Derivation
Derive a key from a password with PBKDF2-SHA-256/512, salt, and iteration count. Educational interoperability tool—not account-storage guidance.
Free to use — no sign-up or login.
Runs entirely in your browser; input is not sent to our servers.
Messages, keys, passwords, plaintext, ciphertext, and files are never stored in
localStorage, history, or analytics payloads.
Use Generate salt or leave blank; blank salts are created on Run.
Minimum 10,000. Default 600,000 for SHA-256 demos.
Salt (Hex)
Derived key (Hex)
Derived key (Base64)
This free PBKDF2 Key Derivation covers Derive a key from a password with PBKDF2-SHA-256/512, salt, and iteration count. Educational interoperability tool—not account-storage guidance.
Enter the PBKDF2 Key Derivation fields, then read the output. Cryptography calculators on this site keep the formula visible beside the form, with no account required.
Using the PBKDF2 Key Derivation
Derive a key from a password with PBKDF2-SHA-256/512, salt, and iteration count. Educational interoperability tool—not account-storage guidance. Typical inputs are Password, Salt (Hex), Iterations and Output bits. How it works beside the form states the identity the PBKDF2 Key Derivation applies.
FAQ
How do I use the PBKDF2 Key Derivation?
Open the PBKDF2 Key Derivation, fill Password, Salt (Hex), Iterations and Output bits, and read the result. Provide a password, a salt (or generate one), an iteration count, and the desired output length in bits. PBKDF2 repeatedly applies HMAC with the chosen PRF (SHA-256 or SHA-512) so a weak password still costs many hash rounds to brute-force. Outputs are the salt and derived key in Hex and Base64.
What formula does the PBKDF2 Key Derivation use?
The PBKDF2 Key Derivation uses the identity in How it works. In words: Provide a password, a salt (or generate one), an iteration count, and the desired output length in bits. PBKDF2 repeatedly applies HMAC with the chosen PRF (SHA-256 or SHA-512) so a weak password still costs many hash rounds to brute-force. Outputs are the salt and derived key in Hex and Base64.