Salt Generator
Generate cryptographically random salts for password hashing, in hexadecimal and base64, to defend against rainbow-table attacks.
Last reviewed by the Radiatus Cloud team
Generate a cryptographically random salt for password hashing.
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
Generate a password salt
A salt is a random value added to a password before it is hashed, and it is essential to secure password storage. This generator produces cryptographically random salts in both hexadecimal and base64. Salting means that two users with the same password get different hashes, and it defeats precomputed rainbow-table attacks, because an attacker would need a separate table for every possible salt. A unique salt should be generated for each password and stored alongside its hash.
Sixteen random bytes is a common, ample salt length, giving an astronomically large number of possible values.
Why salting matters
Without a salt, identical passwords produce identical hashes, so an attacker who cracks one instantly knows every account using that password, and can use precomputed tables to reverse common hashes instantly. A unique random salt per password eliminates both problems, forcing an attacker to attack each password individually. Modern password-hashing algorithms like bcrypt and Argon2 generate and store a salt automatically, but understanding salts is fundamental.
The salt does not need to be secret, only unique and random, so it is stored in plain form with the hash. These salts are generated locally and never transmitted. All generation happens locally in your browser.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
What is a salt?
It is a random value added to a password before hashing, so identical passwords hash differently and rainbow tables are defeated.
How long should a salt be?
Sixteen random bytes is a common and ample length. The key requirement is that it is random and unique per password.
Does the salt need to be secret?
No. A salt only needs to be unique and random, so it is stored in plain form alongside the password hash.
Do bcrypt and Argon2 need a separate salt?
No. They generate and embed a salt automatically. This generator is for custom schemes and for understanding how salting works.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Choose the salt length and format, then generate.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.