crypto.pbkdf2-sha256
PBKDF2 with HMAC-SHA256 (RFC 8018): derive a key from a password and salt, slowly, fast enough for a login request.
1.0.0 · published 2026-10-03 by charlie · Anterra
Pinned by 14 tests, run in TypeScript, Python and Rust.
What it does
PBKDF2 (RFC 8018 section 5.2) with HMAC-SHA256 as its pseudorandom function: it stretches a password and a salt into a key by running HMAC `iterations` times, so that every guess an attacker makes costs the same. It is the algorithm under `auth.password-hash`, which is what an application should normally call; use this directly only to derive keys.
Bytes in and out are lists of integers 0 to 255, as everywhere in the registry (see `encoding.hex`). Encode a text password with `encoding.utf8` first.
For example
pbkdf2_sha256(112, 97, 115, 115, 119, 100, 115, 97, 108, 116, 1, 64)→ 85, 172, 4, 110, 86, 227, 8, 159, 236, 22, 145, 194, 37, 68, 182, 5, 249, 65, 133, 33, 109, 222, 4, 101, 230, 139, 157, 87, 194, 13, 172, 188, 73, 202, 156, 204, 241, 121, 182, 69… RFC 7914 section 11: "passwd" / "salt", 1 iteration, 64 bytes (two blocks)pbkdf2_sha256(80, 97, 115, 115, 119, 111, 114, 100, 78, 97, 67, 108, 80,000, 64)→ 77, 220, 216, 246, 11, 152, 190, 33, 131, 12, 238, 94, 242, 39, 1, 249, 100, 26, 68, 24, 208, 76, 4, 20, 174, 255, 8, 135, 107, 52, 171, 86, 161, 212, 37, 161, 34, 88, 51, 84, 154… RFC 7914 section 11: "Password" / "NaCl", 80,000 iterations, 64 bytespbkdf2_sha256(112, 97, 115, 115, 119, 111, 114, 100, 115, 97, 108, 116, 1, 32)→ 18, 15, 182, 207, 252, 248, 179, 44, 67, 231, 34, 82, 86, 196, 248, 55, 168, 101, 72, 201, 44, 204, 53, 72, 8, 5, 152, 124, 183, 11, 225, 123 RFC 6070's inputs with SHA-256: 1 iteration
The function
The same function in TypeScript, Python and Rust, pinned by the same tests. Pick your language; the choice follows you around the registry.
def pbkdf2_sha256(password: Sequence[int], salt: Sequence[int], iterations: int, key_length: int) -> List[int]
| password | int[] | the password's bytes (encoding.utf8 for text) |
| salt | int[] | random bytes, unique per password; at least 16 in practice |
| iterations | int | the work factor, 1 or more; see the README for a figure |
| key_length | int | bytes of key to derive, 1 or more; 32 is one SHA-256 block |
| returns | int[] | the derived key, keyLength integers from 0 to 255 |
Your code names it in one line, in the file that uses it
from fune.crypto.pbkdf2_sha256 import pbkdf2_sha256 # crypto.pbkdf2-sha256@^1
import hashlib
from typing import Any, List, Sequence
def _check_bytes(value: Any, name: str) -> bytes:
if isinstance(value, (str, dict)) or not hasattr(value, "__len__"):
raise TypeError("%s must be a list of integers from 0 to 255" % name)
for b in value:
if type(b) is not int or b < 0 or b > 255:
raise ValueError("%s must be a list of integers from 0 to 255" % name)
return bytes(value)
def pbkdf2_sha256(password: Sequence[int], salt: Sequence[int], iterations: int, key_length: int) -> List[int]:
"""PBKDF2-HMAC-SHA256 (RFC 8018 section 5.2), from hashlib.
hashlib runs the iterations in C, which is what makes a six-figure
iteration count affordable in a Python request handler.
"""
p = _check_bytes(password, "password")
s = _check_bytes(salt, "salt")
if type(iterations) is not int or iterations < 1:
raise ValueError("iterations must be a whole number of at least 1")
if type(key_length) is not int or key_length < 1:
raise ValueError("keyLength must be a whole number of at least 1")
return list(hashlib.pbkdf2_hmac("sha256", p, s, iterations, key_length))Install
fune build
With that line in your source, in a Python project (language python in fune.project), fune build resolves it and nothing else, pins them in fune.lock, downloads only the Python package of each, and builds the code above into your project’s .fune/build, one readable file per capability with a header linking back here. Or pin a range in fune.project and build in one step:
fune add crypto.pbkdf2-sha256
The manifest, vectors and README with only the Python implementation. Install it without the registry with fune add ./crypto.pbkdf2-sha256-1.0.0-python.fune, or fetch it from a terminal with fune pull crypto.pbkdf2-sha256@1.0.0:python.
The whole function, every language, is one file too: crypto.pbkdf2-sha256-1.0.0.fune, 25,612 bytes, sha256 ddf20f8864a274ed88673b3d29c00fb42f617b380f0b400ef48c77bc67f193b0. It installs into a project of any language.
Customise it in your app
The seams this capability offers. Put a marker directly above a function of your own and fune build wires it into the built code; the package on the registry is not changed, the built file’s header lists it under CUSTOMISED, and fune hooks lists every hook in the project. How hooks work.
before — your function gets the arguments and returns them, changed or not, or throws to refuse the call.
# fune: before crypto.pbkdf2-sha256
after — your function gets the result and the arguments, and returns the final result.
# fune: after crypto.pbkdf2-sha256
replace — it requires no other capability, so there is no dependency to replace.
step — your function runs at a numbered point inside the function’s body, receives the in-scope values it names as parameters, and may return replacements. List the points with fune show crypto.pbkdf2-sha256 --steps.
# fune: step crypto.pbkdf2-sha256 after <n|label>
Tests
A version published now needs at least 8 tests for every function, and one that expects the error for each function that throws; the registry refuses it otherwise. fune verify --all runs each case in TypeScript, Python and Rust, and a project runs them again with fune verify. This page lists the cases; it does not run them. The exact JSON is vectors.json.
| Case | Arguments | Expected | |
|---|---|---|---|
| RFC 7914 section 11: "passwd" / "salt", 1 iteration, 64 bytes (two blocks) | 112, 97, 115, 115, 119, 100, 115, 97, 108, 116, 1, 64 | → | 85, 172, 4, 110, 86, 227, 8, 159, 236, 22, 145, 194, 37, 68, 182, 5, 249, 65, 133, 33, 109, 222, 4, 101, 230, 139, 157, 87, 194, 13, 172, 188, 73, 202, 156, 204, 241, 121, 182, 69… |
| RFC 7914 section 11: "Password" / "NaCl", 80,000 iterations, 64 bytes | 80, 97, 115, 115, 119, 111, 114, 100, 78, 97, 67, 108, 80,000, 64 | → | 77, 220, 216, 246, 11, 152, 190, 33, 131, 12, 238, 94, 242, 39, 1, 249, 100, 26, 68, 24, 208, 76, 4, 20, 174, 255, 8, 135, 107, 52, 171, 86, 161, 212, 37, 161, 34, 88, 51, 84, 154… |
| RFC 6070's inputs with SHA-256: 1 iteration | 112, 97, 115, 115, 119, 111, 114, 100, 115, 97, 108, 116, 1, 32 | → | 18, 15, 182, 207, 252, 248, 179, 44, 67, 231, 34, 82, 86, 196, 248, 55, 168, 101, 72, 201, 44, 204, 53, 72, 8, 5, 152, 124, 183, 11, 225, 123 |
| RFC 6070's inputs with SHA-256: 2 iterations | 112, 97, 115, 115, 119, 111, 114, 100, 115, 97, 108, 116, 2, 32 | → | 174, 77, 12, 149, 175, 107, 70, 211, 45, 10, 223, 249, 40, 240, 109, 208, 42, 48, 63, 142, 243, 194, 81, 223, 214, 226, 216, 90, 149, 71, 76, 67 |
| RFC 6070's inputs with SHA-256: 4096 iterations | 112, 97, 115, 115, 119, 111, 114, 100, 115, 97, 108, 116, 4,096, 32 | → | 197, 228, 120, 213, 146, 136, 200, 65, 170, 83, 13, 182, 132, 92, 76, 141, 150, 40, 147, 160, 1, 206, 78, 17, 164, 150, 56, 115, 170, 152, 19, 74 |
| RFC 6070's inputs with SHA-256: long password and salt, 40 bytes cut from two blocks | 112, 97, 115, 115, 119, 111, 114, 100, 80, 65, 83, 83, 87, 79, 82, 68, 112, 97, 115, 115, 119, 111, 114, 100, 115, 97, 108, 116, 83, 65, 76, 84, 115, 97, 108, 116, 83, 65, 76, 84,… | → | 52, 140, 137, 219, 203, 211, 43, 47, 50, 216, 20, 184, 17, 110, 132, 207, 43, 23, 52, 126, 188, 24, 0, 24, 28, 78, 42, 31, 184, 221, 83, 225, 198, 53, 81, 140, 125, 172, 71, 233 |
| RFC 6070's inputs with SHA-256: NUL bytes inside password and salt, 16 bytes | 112, 97, 115, 115, 0, 119, 111, 114, 100, 115, 97, 0, 108, 116, 4,096, 16 | → | 137, 182, 157, 5, 22, 248, 41, 137, 60, 105, 98, 38, 101, 10, 134, 135 |
| a password longer than 64 bytes is hashed first, as HMAC requires (hashlib as the reference) | 65, 66, 67, 68, 69, 70, 71, 72, 73, 74, 75, 76, 77, 78, 79, 80, 81, 82, 83, 84, 85, 86, 87, 88, 89, 90, 65, 66, 67, 68, 69, 70, 71, 72, 73, 74, 75, 76, 77, 78, 79, 80, 81, 82, 83,… | → | 9, 49, 133, 24, 41, 76, 78, 138, 90, 59, 13, 19, 48, 156, 20, 90, 25, 210, 255, 202, 49, 170, 31, 31, 35, 246, 76, 127, 54, 202, 172, 146 |
| an empty password and a one-byte key (hashlib as the reference) | , 115, 97, 108, 116, 2, 1 | → | 98 |
| zero iterations | 112, 115, 0, 32 | → | error: iterations must be a whole number of at least 1 |
Show the other 4 tests
| Case | Arguments | Expected | |
|---|---|---|---|
| a fractional iteration count | 112, 115, 1.5, 32 | → | error: iterations must be a whole number of at least 1 |
| a zero-length key | 112, 115, 1, 0 | → | error: keyLength must be a whole number of at least 1 |
| a salt byte above 255 | 112, 300, 1, 32 | → | error: salt must be a list of integers from 0 to 255 |
| a password given as text rather than bytes | password, 115, 1, 32 | → | error: password must be a list of integers from 0 to 255 |
More from the author
**How many iterations.** OWASP's Password Storage Cheat Sheet recommends 600,000 for PBKDF2-HMAC-SHA256 (2023). Measured on an Apple Silicon laptop, one 32-byte key at a time:
| iterations | Python (hashlib) | Rust (release) | TypeScript (Node 24) | |-----------:|-----------------:|---------------:|---------------------:| | 100,000 | 8 ms | 48 ms | 39 ms | | 310,000 | 24 ms | 95 ms | 113 ms | | 600,000 | 47 ms | 178 ms | 222 ms |
so 600,000 is affordable in a login request in every language. Record the count with the hash (`auth.password-hash` does) so it can be raised later.
**Implementation.** Python uses the standard library's `hashlib.pbkdf2_hmac`, which runs the loop in C. TypeScript and Rust are written out with no `node:crypto` or crates; they precompute the HMAC key's inner and outer pad states once, and hash each 32-byte intermediate as a single pre-padded block, which halves the work of calling HMAC naively and allocates nothing inside the loop. That needs SHA-256's compression function itself, which `crypto.sha256` does not expose, so it is repeated here rather than required.
A password longer than 64 bytes is hashed first, as HMAC requires (RFC 2104), and the key may be longer than 32 bytes: each further 32-byte block runs the full iteration count again (RFC 8018's `T_i`), so ask for only what you use.
Empty passwords and empty salts are computed, as the RFC allows; refusing a weak salt is `auth.password-hash`'s job (it wants 16 bytes or more).
Sources: RFC 8018, PKCS #5: Password-Based Cryptography Specification Version 2.1, section 5.2 (https://www.rfc-editor.org/rfc/rfc8018); the PBKDF2-HMAC-SHA256 test vectors of RFC 7914 section 11 (https://www.rfc-editor.org/rfc/rfc7914#section-11); RFC 6070's inputs (https://www.rfc-editor.org/rfc/rfc6070) with their published SHA-256 results, each confirmed against Python's hashlib; OWASP Password Storage Cheat Sheet (https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html).
Files
| Path | Bytes |
|---|---|
| README.md | 2,634 |
| impl/python.py | 1,166 |
| impl/rust.rs | 7,251 |
| impl/typescript.ts | 7,962 |
| vectors.json | 4,123 |