You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Store user passwords with these — never with fast hashes like sha256 or wflhash256 alone. For sensitive credentials, prefer a multi-hash pre-mix (e.g. WFLHASH then sha256) thenhash_password.
Function
Signature
Returns
Description
hash_password
hash_password of <password>
Text
Hash a password (Argon2id default)
verify_password
verify_password of <password> and <hash>
Boolean
Verify against any supported hash
argon2_hash
argon2_hash of <password>
Text
Argon2id hash
argon2_verify
argon2_verify of <password> and <hash>
Boolean
Verify Argon2 hash
bcrypt_hash
bcrypt_hash of <password>
Text
bcrypt hash
bcrypt_verify
bcrypt_verify of <password> and <hash>
Boolean
Verify bcrypt hash
scrypt_hash
scrypt_hash of <password>
Text
scrypt hash
scrypt_verify
scrypt_verify of <password> and <hash>
Boolean
Verify scrypt hash
pbkdf2_hash
pbkdf2_hash of <password>
Text
PBKDF2-HMAC-SHA256 hash
pbkdf2_verify
pbkdf2_verify of <password> and <hash>
Boolean
Verify PBKDF2 hash
Auth & session primitives (3 functions)
Function
Signature
Returns
Description
pbkdf2_hmac_sha256
pbkdf2_hmac_sha256 of <password> and <salt> and <iterations> and <length>
Text
Raw PBKDF2-HMAC-SHA256 key derivation (hex)
constant_time_equals
constant_time_equals of <a> and <b>
Boolean
Timing-safe string comparison
secure_random_bytes
secure_random_bytes of <n>
Text
n CSPRNG bytes as hex (for salts, tokens, session IDs)
Security: For sensitive data (especially passwords), use more than one hash. Passwords: multi-hash pre-mix then hash_password/verify_password. WFLHASH is experimental — please test it. For production integrity, dual-hash: WFLHASH then a known-good algorithm (sha256 of wflhash256 of data). Use sha256 / hmac_sha256 alone when interoperating with external services.