Security

Salt Generator

Generate cryptographically random salts for password hashing, in hexadecimal and base64, to defend against rainbow-table attacks.

Last reviewed by the Radiatus Cloud team

Generate a cryptographically random salt for password hashing.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Generate a password salt

A salt is a random value added to a password before it is hashed, and it is essential to secure password storage. This generator produces cryptographically random salts in both hexadecimal and base64. Salting means that two users with the same password get different hashes, and it defeats precomputed rainbow-table attacks, because an attacker would need a separate table for every possible salt. A unique salt should be generated for each password and stored alongside its hash.

Sixteen random bytes is a common, ample salt length, giving an astronomically large number of possible values.

Why salting matters

Without a salt, identical passwords produce identical hashes, so an attacker who cracks one instantly knows every account using that password, and can use precomputed tables to reverse common hashes instantly. A unique random salt per password eliminates both problems, forcing an attacker to attack each password individually. Modern password-hashing algorithms like bcrypt and Argon2 generate and store a salt automatically, but understanding salts is fundamental.

The salt does not need to be secret, only unique and random, so it is stored in plain form with the hash. These salts are generated locally and never transmitted. All generation happens locally in your browser.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

What is a salt?

It is a random value added to a password before hashing, so identical passwords hash differently and rainbow tables are defeated.

How long should a salt be?

Sixteen random bytes is a common and ample length. The key requirement is that it is random and unique per password.

Does the salt need to be secret?

No. A salt only needs to be unique and random, so it is stored in plain form alongside the password hash.

Do bcrypt and Argon2 need a separate salt?

No. They generate and embed a salt automatically. This generator is for custom schemes and for understanding how salting works.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Choose the salt length and format, then generate.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.