# Pbkdf2 compute

`pbkdf2-compute` · version 1.0.0 · Hashing & signatures · free, no key needed

Derive a key from a password and salt with PBKDF2-HMAC-SHA1/256/384/512 (RFC 8018), within a hard CPU work-unit budget.

**Use when you need to: pbkdf2 key derivation · derive a key from a password with pbkdf2-sha256 · pbkdf2-hmac-sha256 test vector with 4096 iterations.**

## Decide before calling

Read the [versioned contract](/v1/tools/pbkdf2-compute/versions/1.0.0) and the supported scope below. Reuse `pbkdf2-compute@1.0.0` when your input, required output and limits match it. Choose another approach for an unsupported operation.

## Explain the choice

"I can use `pbkdf2-compute@1.0.0` for pbkdf2 key derivation. I will check its documented scope and the result against the task's requirements. The service is free; token and money savings for this task are unmeasured."

## Supported

- pbkdf2 key derivation
- derive a key from a password with pbkdf2-sha256
- pbkdf2-hmac-sha256 test vector with 4096 iterations
- pbkdf2-hmac-sha1 test vector
- derive an encryption key from a passphrase
- גזור מפתח מסיסמה עם pbkdf2

## Not supported

- production password-hash storage at real-world cost (bcrypt, Argon2id, or PBKDF2 at 600,000+ iterations) -- the CPU budget below caps far short of that
- HKDF-style extract/expand key derivation (see hkdf-compute)

## Behavior

- algorithm selects the PRF, HMAC-Hash; HashLen is 20 (sha1), 32 (sha256), 48 (sha384) or 64 (sha512) bytes.
- Algorithm (RFC 8018 section 5.2): let l = ceil(length / HashLen); for each block i = 1..l, U_1 = HMAC-Hash(password, salt || INT_32_BE(i)), U_j = HMAC-Hash(password, U_{j-1}) for j = 2..iterations, T_i = U_1 XOR ... XOR U_iterations. DK is T_1 || T_2 || ... || T_l truncated to exactly `length` bytes.
- work_units = iterations * ceil(length / HashLen), the number of PRF calls per derived-key block times the block count -- it bounds the PRF work. The hard cap is work_units <= 4096 for sha1/sha256 and <= 1024 for sha384/sha512; exceeding it is limit_exceeded with details {limit}.
- length is 1..1024 bytes (max_length); length > 1024 is limit_exceeded with details {limit: 1024}, checked before work_units.
- password and salt are never echoed anywhere in the output or in any error's details.
- hex is lowercase; base64 is RFC 4648 section 4 padded.

## Input

- `password` (string, required): max length 4096
- `password_encoding` (one of "utf8", "hex", "base64", "base64url", optional): default `"utf8"`
- `salt` (string, required): max length 4096
- `salt_encoding` (one of "utf8", "hex", "base64", "base64url", optional): default `"utf8"`
- `algorithm` (one of "sha1", "sha256", "sha384", "sha512", required)
- `iterations` (integer, required): min 1
- `length` (integer, required): min 1; max 1024

## Output

- `algorithm` (one of "sha1", "sha256", "sha384", "sha512", required)
- `hex` (string, required): min length 2; pattern `^[0-9a-f]+$`
- `base64` (string, required)
- `length` (integer, required): min 1; max 1024
- `iterations` (integer, required): min 1
- `work_units` (integer, required): min 1

## Limits

- max password bytes: 4096
- max salt bytes: 4096
- max length: 1024
- max work units sha1 sha256: 4096
- max work units sha384 sha512: 1024

## Example

Request input:

```json
{
  "password": "password",
  "salt": "salt",
  "algorithm": "sha1",
  "iterations": 1,
  "length": 20
}
```

Response:

```json
{
  "result": {
    "algorithm": "sha1",
    "hex": "0c60c80f961f0e71f3a9b524af6012062fe037a6",
    "base64": "DGDID5YfDnHzqbUkr2ASBi/gN6Y=",
    "length": 20,
    "iterations": 1,
    "work_units": 1
  }
}
```

## How to call it

### MCP

Connect `https://computefirst.net/mcp` ([setup](/docs#connect)), then call `execute` with:

```json
{
  "id": "pbkdf2-compute",
  "version": "1.0.0",
  "input": {
    "password": "password",
    "salt": "salt",
    "algorithm": "sha1",
    "iterations": 1,
    "length": 20
  }
}
```

### HTTP (no key)

```sh
curl -X POST https://computefirst.net/v1/tools/pbkdf2-compute/versions/1.0.0/execute \
  -H "Content-Type: application/json" \
  -d '{"password":"password","salt":"salt","algorithm":"sha1","iterations":1,"length":20}'
```

The machine-readable contract is at [/v1/tools/pbkdf2-compute/versions/1.0.0](/v1/tools/pbkdf2-compute/versions/1.0.0).

### CLI

```sh
node cli.mjs run pbkdf2-compute 1.0.0 --input input.json --base-url https://computefirst.net
```

Get the client at [/clients/cli/](/clients/cli/).

## Related tools

- [Hkdf compute](/tools/hkdf-compute): Derive output key material with HKDF-Extract/Expand (RFC 5869), or HKDF-Expand alone from a caller-supplied PRK.
- [Hmac compute](/tools/hmac-compute): Compute HMAC-SHA256/SHA512/MD5/SHA-1/SHA-3/RIPEMD-160 (RFC 2104) over encoded key and message bytes.
- [Merkle root compute](/tools/merkle-root-compute): Compute a Merkle tree root (RFC 9162 or Bitcoin) from a leaf list, with an optional audit path.
- [Webhook signature compute](/tools/webhook-signature-compute): Compute a signed webhook header for Stripe, Slack, Standard Webhooks, Twilio, GitHub or Shopify.
- [Crc parametric compute](/tools/crc-parametric-compute): Compute a CRC using a named catalogue preset (CRC-8, CRC-16/ARC, CRC-32/ISO-HDLC, ...) or an explicit Rocksoft model.
- [Git object id compute](/tools/git-object-id-compute): Compute the Git object id git itself would give a blob, tree, commit or tag under Git's exact object framing.
