Security

Password Hashing Cost Calculator

Choose bcrypt work factors, Argon2 memory and iteration parameters or PBKDF2 iteration counts from a target verification time, and see the attacker cost each setting imposes.

Last reviewed by the Radiatus Cloud team

Recommended parameters appear here.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

A password hash should be deliberately slow

General purpose hashes are designed to be fast, which is precisely wrong for passwords. Commodity hardware computes billions of SHA-256 hashes per second, so a leaked table of unsalted SHA-256 password hashes is cracked at enormous rates. Purpose built password hashes take a cost parameter that makes each computation expensive, so an attacker who steals the database faces a work factor per guess rather than a rounding error. The parameter is the entire security property.

Tune to time, not to a number you read somewhere

The right work factor is whatever makes verification take an acceptable amount of time on your production hardware. OWASP's guidance is to target somewhere between 200 milliseconds and one second per verification. A bcrypt cost of 12 might take 250 milliseconds on one server and 900 on another, so copying a number without measuring produces either an insecure setting or a login endpoint that falls over. Every increment of one in the bcrypt cost doubles the work.

Memory hardness is what stops GPUs

bcrypt resists GPU attack reasonably well but Argon2 and scrypt resist it far better, because they require large amounts of memory that a GPU or ASIC cannot cheaply replicate across thousands of parallel cores. Argon2id, the hybrid variant, is the current recommendation from OWASP and the Password Hashing Competition, with a minimum of 19 megabytes of memory and two iterations. PBKDF2 has no memory cost at all and needs a very high iteration count to compensate, which is why it survives mainly where FIPS validation is required.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

What bcrypt cost should I use?

Whatever produces 200 to 500 milliseconds on your production hardware, which today is typically 12 or 13. Each increment doubles the work, so cost 12 is twice as expensive as 11. Measure rather than copy a number.

What Argon2 parameters are recommended?

OWASP suggests Argon2id with at least 19 MiB of memory, 2 iterations and parallelism of 1, or 46 MiB with 1 iteration. More memory is generally better than more iterations, because memory is what defeats GPU and ASIC attackers.

How many PBKDF2 iterations?

OWASP guidance is 600,000 for PBKDF2-HMAC-SHA256 and 210,000 for SHA-512. The numbers are high because PBKDF2 has no memory cost, so iteration count is the only lever available.

Does a slow hash hurt my login endpoint?

It uses CPU per login, so it must be sized against peak login rate. The calculator estimates the concurrent capacity needed. It also makes hashing a denial of service surface, which is why rate limiting on the login endpoint matters alongside it.

Should I re-hash existing passwords?

You cannot re-hash without the plaintext, so the standard approach is to upgrade on next successful login: verify against the old hash, then immediately re-hash with the new parameters. Store the algorithm and parameters with each hash so both can coexist.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Set your target hashing time and login volume to get recommended parameters for each algorithm.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.