Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Cryptography
  3. password-hashes

password-hashes

Rust

A collection of password hashing algorithms and key derivation functions implemented in pure Rust.

GitHubGitHub
912 stars115 forks0 contributors

What is password-hashes?

RustCrypto/password-hashes is a collection of password hashing algorithms and key derivation functions implemented in pure Rust. It provides secure implementations of algorithms like Argon2, bcrypt, PBKDF2, and scrypt for storing and verifying passwords in Rust applications. The project solves the problem of securely handling user passwords by offering modern, audited cryptographic primitives.

Target Audience

Rust developers building applications that require secure password storage and authentication systems, particularly those implementing user login functionality or password-based encryption.

Value Proposition

Developers choose this collection because it provides pure Rust implementations of multiple password hashing algorithms with a unified API, eliminating C dependencies and ensuring memory safety. It follows cryptographic best practices and references OWASP guidelines for secure password storage.

Overview

Password hashing functions / KDFs

Use Cases

Best For

  • Implementing secure password storage in Rust web applications
  • Building authentication systems with multiple password hashing algorithm support
  • Migrating legacy password hashes to modern algorithms like Argon2
  • Developing password managers or credential storage tools in Rust
  • Creating educational tools for learning about password hashing algorithms
  • Benchmarking different password hashing algorithms in Rust environments

Not Ideal For

  • Applications built in languages other than Rust that require password hashing
  • Projects needing integrated authentication with user management, session handling, and social logins out-of-the-box
  • Systems where hardware-accelerated password hashing (e.g., via GPU or specialized ASICs) is critical for maximum performance
  • Teams preferring a single, pre-configured algorithm without the burden of selecting and tuning from multiple options

Pros & Cons

Pros

Multiple Algorithm Support

Supports seven algorithms including Argon2, bcrypt, and scrypt, providing flexibility to choose based on security needs and compatibility, as detailed in the README's table.

Pure Rust Safety

Implemented entirely in Rust with no C dependencies, ensuring memory safety and eliminating FFI complexities, which is emphasized in the project's philosophy.

Unified Verification API

Offers a common trait-based interface (PasswordVerifier) for verifying passwords across different algorithms, simplifying code as shown in the usage example.

OWASP Compliance Guidance

References the OWASP Password Storage Cheat Sheet directly, helping developers select secure algorithms following modern best practices.

Flexible Licensing

Dual-licensed under Apache 2.0 or MIT, allowing easy integration into both open-source and commercial projects without licensing conflicts.

Cons

Fragmented Crate Structure

Each algorithm is a separate crate, requiring multiple dependencies and potentially increasing setup complexity and maintenance overhead.

Performance Trade-offs

Prioritizes correctness and safety over performance optimizations, which may result in slower hashing compared to optimized C libraries, as noted in the philosophy.

No Opinionated Defaults

Lacks a recommended default algorithm or configuration, forcing developers to make informed choices that could lead to suboptimal or insecure setups.

Breaking Change Policy

MSRV bumps are treated as breaking changes with minor version updates, potentially causing disruption in long-term projects, as stated in the MSRV policy.

Frequently Asked Questions

Quick Stats

Stars912
Forks115
Contributors0
Open Issues9
Last commit15 days ago
CreatedSince 2017

Tags

#key-derivation#authentication#bcrypt#password-hashing#security#password-storage#cryptography#rust#kdf#argon2

Built With

R
Rust

Included in

Cryptography6.8k
Auto-fetched 21 hours ago

Related Projects

rustlsrustls

A modern TLS library in Rust

Stars7,656
Forks905
Last commit1 day ago
BLAKE3BLAKE3

the official Rust and C implementations of the BLAKE3 cryptographic hash function

Stars6,460
Forks490
Last commit5 days ago
OckamOckam

Orchestrate end-to-end encryption, cryptographic identities, mutual authentication, and authorization policies between distributed applications – at massive scale.

Stars4,635
Forks555
Last commit9 months ago
ringring

An experiment.

Stars4,111
Forks806
Last commit2 months ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub