Derive secure keys with customizable iterations, salts, and SHA hashes.
Execution runs 100% locally inside the browser sandbox using HTML5 Canvas, Web Cryptography Subtle API, and Web Workers. Zero egress.
Zero network latency. Operates completely offline with zero dependencies on third-party backend servers or cloud services.
Built according to official RFC specifications, cryptographic test vectors, and enterprise-grade data transformation standards.
Input your plain password string and salt value (or generate a secure random salt).
Configure iteration count (e.g., 100,000) and hash digest algorithm (SHA-256 or SHA-512).
Copy the derived cryptographic key in hexadecimal or Base64 format.
Yes, it uses the native window.crypto.subtle Web Cryptography API for hardware-accelerated computation.
OWASP recommends at least 600,000 iterations for PBKDF2-HMAC-SHA256 in password storage.
Zero-egress companion tools in the Security & Network suite
Audit CSP, HSTS, X-Frame-Options, and security headers with OWASP grading (A+ to F).
Measure cryptographic randomness, Shannon entropy (0-8 bits/byte), Chi-square test, and byte distributions.
Generate secure RFC 6238 Base32 TOTP secret keys and standard otpauth:// URIs for Google Authenticator.
Construct and validate HTTP CSP headers and meta tags.