Functional Weave
Code in Python

crypto.pbkdf2-sha256

PBKDF2 with HMAC-SHA256 (RFC 8018): derive a key from a password and salt, slowly, fast enough for a login request.

1.0.0 · published 2026-10-03 by charlie · Anterra

Pinned by 14 tests, run in TypeScript, Python and Rust.

What it does

PBKDF2 (RFC 8018 section 5.2) with HMAC-SHA256 as its pseudorandom function: it stretches a password and a salt into a key by running HMAC `iterations` times, so that every guess an attacker makes costs the same. It is the algorithm under `auth.password-hash`, which is what an application should normally call; use this directly only to derive keys.

Bytes in and out are lists of integers 0 to 255, as everywhere in the registry (see `encoding.hex`). Encode a text password with `encoding.utf8` first.

For example

  • pbkdf2_sha256(112, 97, 115, 115, 119, 100, 115, 97, 108, 116, 1, 64) → 85, 172, 4, 110, 86, 227, 8, 159, 236, 22, 145, 194, 37, 68, 182, 5, 249, 65, 133, 33, 109, 222, 4, 101, 230, 139, 157, 87, 194, 13, 172, 188, 73, 202, 156, 204, 241, 121, 182, 69… RFC 7914 section 11: "passwd" / "salt", 1 iteration, 64 bytes (two blocks)
  • pbkdf2_sha256(80, 97, 115, 115, 119, 111, 114, 100, 78, 97, 67, 108, 80,000, 64) → 77, 220, 216, 246, 11, 152, 190, 33, 131, 12, 238, 94, 242, 39, 1, 249, 100, 26, 68, 24, 208, 76, 4, 20, 174, 255, 8, 135, 107, 52, 171, 86, 161, 212, 37, 161, 34, 88, 51, 84, 154… RFC 7914 section 11: "Password" / "NaCl", 80,000 iterations, 64 bytes
  • pbkdf2_sha256(112, 97, 115, 115, 119, 111, 114, 100, 115, 97, 108, 116, 1, 32) → 18, 15, 182, 207, 252, 248, 179, 44, 67, 231, 34, 82, 86, 196, 248, 55, 168, 101, 72, 201, 44, 204, 53, 72, 8, 5, 152, 124, 183, 11, 225, 123 RFC 6070's inputs with SHA-256: 1 iteration

The function

The same function in TypeScript, Python and Rust, pinned by the same tests. Pick your language; the choice follows you around the registry.

def pbkdf2_sha256(password: Sequence[int], salt: Sequence[int], iterations: int, key_length: int) -> List[int]
passwordint[]the password's bytes (encoding.utf8 for text)
saltint[]random bytes, unique per password; at least 16 in practice
iterationsintthe work factor, 1 or more; see the README for a figure
key_lengthintbytes of key to derive, 1 or more; 32 is one SHA-256 block
returnsint[]the derived key, keyLength integers from 0 to 255

Your code names it in one line, in the file that uses it

from fune.crypto.pbkdf2_sha256 import pbkdf2_sha256  # crypto.pbkdf2-sha256@^1
impl/python.py · 26 lines · open · raw
import hashlib
from typing import Any, List, Sequence


def _check_bytes(value: Any, name: str) -> bytes:
    if isinstance(value, (str, dict)) or not hasattr(value, "__len__"):
        raise TypeError("%s must be a list of integers from 0 to 255" % name)
    for b in value:
        if type(b) is not int or b < 0 or b > 255:
            raise ValueError("%s must be a list of integers from 0 to 255" % name)
    return bytes(value)


def pbkdf2_sha256(password: Sequence[int], salt: Sequence[int], iterations: int, key_length: int) -> List[int]:
    """PBKDF2-HMAC-SHA256 (RFC 8018 section 5.2), from hashlib.

    hashlib runs the iterations in C, which is what makes a six-figure
    iteration count affordable in a Python request handler.
    """
    p = _check_bytes(password, "password")
    s = _check_bytes(salt, "salt")
    if type(iterations) is not int or iterations < 1:
        raise ValueError("iterations must be a whole number of at least 1")
    if type(key_length) is not int or key_length < 1:
        raise ValueError("keyLength must be a whole number of at least 1")
    return list(hashlib.pbkdf2_hmac("sha256", p, s, iterations, key_length))

Install

fune build

With that line in your source, in a Python project (language python in fune.project), fune build resolves it and nothing else, pins them in fune.lock, downloads only the Python package of each, and builds the code above into your project’s .fune/build, one readable file per capability with a header linking back here. Or pin a range in fune.project and build in one step:

fune add crypto.pbkdf2-sha256
Download for Python crypto.pbkdf2-sha256-1.0.0-python.fune · 9,945 bytes sha256 25067faa0cedce756a404cecefbd40b5a4ff162dbecb917ef87e88ca08e01fc6

The manifest, vectors and README with only the Python implementation. Install it without the registry with fune add ./crypto.pbkdf2-sha256-1.0.0-python.fune, or fetch it from a terminal with fune pull crypto.pbkdf2-sha256@1.0.0:python.

The whole function, every language, is one file too: crypto.pbkdf2-sha256-1.0.0.fune, 25,612 bytes, sha256 ddf20f8864a274ed88673b3d29c00fb42f617b380f0b400ef48c77bc67f193b0. It installs into a project of any language.

Customise it in your app

The seams this capability offers. Put a marker directly above a function of your own and fune build wires it into the built code; the package on the registry is not changed, the built file’s header lists it under CUSTOMISED, and fune hooks lists every hook in the project. How hooks work.

before — your function gets the arguments and returns them, changed or not, or throws to refuse the call.

# fune: before crypto.pbkdf2-sha256

after — your function gets the result and the arguments, and returns the final result.

# fune: after crypto.pbkdf2-sha256

replace — it requires no other capability, so there is no dependency to replace.

step — your function runs at a numbered point inside the function’s body, receives the in-scope values it names as parameters, and may return replacements. List the points with fune show crypto.pbkdf2-sha256 --steps.

# fune: step crypto.pbkdf2-sha256 after <n|label>

Tests

A version published now needs at least 8 tests for every function, and one that expects the error for each function that throws; the registry refuses it otherwise. fune verify --all runs each case in TypeScript, Python and Rust, and a project runs them again with fune verify. This page lists the cases; it does not run them. The exact JSON is vectors.json.

CaseArgumentsExpected
RFC 7914 section 11: "passwd" / "salt", 1 iteration, 64 bytes (two blocks) 112, 97, 115, 115, 119, 100, 115, 97, 108, 116, 1, 64 → 85, 172, 4, 110, 86, 227, 8, 159, 236, 22, 145, 194, 37, 68, 182, 5, 249, 65, 133, 33, 109, 222, 4, 101, 230, 139, 157, 87, 194, 13, 172, 188, 73, 202, 156, 204, 241, 121, 182, 69…
RFC 7914 section 11: "Password" / "NaCl", 80,000 iterations, 64 bytes 80, 97, 115, 115, 119, 111, 114, 100, 78, 97, 67, 108, 80,000, 64 → 77, 220, 216, 246, 11, 152, 190, 33, 131, 12, 238, 94, 242, 39, 1, 249, 100, 26, 68, 24, 208, 76, 4, 20, 174, 255, 8, 135, 107, 52, 171, 86, 161, 212, 37, 161, 34, 88, 51, 84, 154…
RFC 6070's inputs with SHA-256: 1 iteration 112, 97, 115, 115, 119, 111, 114, 100, 115, 97, 108, 116, 1, 32 → 18, 15, 182, 207, 252, 248, 179, 44, 67, 231, 34, 82, 86, 196, 248, 55, 168, 101, 72, 201, 44, 204, 53, 72, 8, 5, 152, 124, 183, 11, 225, 123
RFC 6070's inputs with SHA-256: 2 iterations 112, 97, 115, 115, 119, 111, 114, 100, 115, 97, 108, 116, 2, 32 → 174, 77, 12, 149, 175, 107, 70, 211, 45, 10, 223, 249, 40, 240, 109, 208, 42, 48, 63, 142, 243, 194, 81, 223, 214, 226, 216, 90, 149, 71, 76, 67
RFC 6070's inputs with SHA-256: 4096 iterations 112, 97, 115, 115, 119, 111, 114, 100, 115, 97, 108, 116, 4,096, 32 → 197, 228, 120, 213, 146, 136, 200, 65, 170, 83, 13, 182, 132, 92, 76, 141, 150, 40, 147, 160, 1, 206, 78, 17, 164, 150, 56, 115, 170, 152, 19, 74
RFC 6070's inputs with SHA-256: long password and salt, 40 bytes cut from two blocks 112, 97, 115, 115, 119, 111, 114, 100, 80, 65, 83, 83, 87, 79, 82, 68, 112, 97, 115, 115, 119, 111, 114, 100, 115, 97, 108, 116, 83, 65, 76, 84, 115, 97, 108, 116, 83, 65, 76, 84,… → 52, 140, 137, 219, 203, 211, 43, 47, 50, 216, 20, 184, 17, 110, 132, 207, 43, 23, 52, 126, 188, 24, 0, 24, 28, 78, 42, 31, 184, 221, 83, 225, 198, 53, 81, 140, 125, 172, 71, 233
RFC 6070's inputs with SHA-256: NUL bytes inside password and salt, 16 bytes 112, 97, 115, 115, 0, 119, 111, 114, 100, 115, 97, 0, 108, 116, 4,096, 16 → 137, 182, 157, 5, 22, 248, 41, 137, 60, 105, 98, 38, 101, 10, 134, 135
a password longer than 64 bytes is hashed first, as HMAC requires (hashlib as the reference) 65, 66, 67, 68, 69, 70, 71, 72, 73, 74, 75, 76, 77, 78, 79, 80, 81, 82, 83, 84, 85, 86, 87, 88, 89, 90, 65, 66, 67, 68, 69, 70, 71, 72, 73, 74, 75, 76, 77, 78, 79, 80, 81, 82, 83,… → 9, 49, 133, 24, 41, 76, 78, 138, 90, 59, 13, 19, 48, 156, 20, 90, 25, 210, 255, 202, 49, 170, 31, 31, 35, 246, 76, 127, 54, 202, 172, 146
an empty password and a one-byte key (hashlib as the reference) , 115, 97, 108, 116, 2, 1 → 98
zero iterations 112, 115, 0, 32 → error: iterations must be a whole number of at least 1
Show the other 4 tests
CaseArgumentsExpected
a fractional iteration count 112, 115, 1.5, 32 → error: iterations must be a whole number of at least 1
a zero-length key 112, 115, 1, 0 → error: keyLength must be a whole number of at least 1
a salt byte above 255 112, 300, 1, 32 → error: salt must be a list of integers from 0 to 255
a password given as text rather than bytes password, 115, 1, 32 → error: password must be a list of integers from 0 to 255

More from the author

**How many iterations.** OWASP's Password Storage Cheat Sheet recommends 600,000 for PBKDF2-HMAC-SHA256 (2023). Measured on an Apple Silicon laptop, one 32-byte key at a time:

| iterations | Python (hashlib) | Rust (release) | TypeScript (Node 24) | |-----------:|-----------------:|---------------:|---------------------:| | 100,000 | 8 ms | 48 ms | 39 ms | | 310,000 | 24 ms | 95 ms | 113 ms | | 600,000 | 47 ms | 178 ms | 222 ms |

so 600,000 is affordable in a login request in every language. Record the count with the hash (`auth.password-hash` does) so it can be raised later.

**Implementation.** Python uses the standard library's `hashlib.pbkdf2_hmac`, which runs the loop in C. TypeScript and Rust are written out with no `node:crypto` or crates; they precompute the HMAC key's inner and outer pad states once, and hash each 32-byte intermediate as a single pre-padded block, which halves the work of calling HMAC naively and allocates nothing inside the loop. That needs SHA-256's compression function itself, which `crypto.sha256` does not expose, so it is repeated here rather than required.

A password longer than 64 bytes is hashed first, as HMAC requires (RFC 2104), and the key may be longer than 32 bytes: each further 32-byte block runs the full iteration count again (RFC 8018's `T_i`), so ask for only what you use.

Empty passwords and empty salts are computed, as the RFC allows; refusing a weak salt is `auth.password-hash`'s job (it wants 16 bytes or more).

Sources: RFC 8018, PKCS #5: Password-Based Cryptography Specification Version 2.1, section 5.2 (https://www.rfc-editor.org/rfc/rfc8018); the PBKDF2-HMAC-SHA256 test vectors of RFC 7914 section 11 (https://www.rfc-editor.org/rfc/rfc7914#section-11); RFC 6070's inputs (https://www.rfc-editor.org/rfc/rfc6070) with their published SHA-256 results, each confirmed against Python's hashlib; OWASP Password Storage Cheat Sheet (https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html).

Files

PathBytes
README.md2,634
impl/python.py1,166
impl/rust.rs7,251
impl/typescript.ts7,962
vectors.json4,123