Skip to content
securepassword · 256 bits · 2015

Argon2id

Winner of the Password Hashing Competition. Memory-hard, side-channel resistant, three tunable knobs. The 2026 default.

By ·

Argon2id is the recommended password-hashing function in OWASP's 2025 cheatsheet, in NIST SP 800-63B, and in essentially every other modern guidance document. It's the winning entry of the 2015 Password Hashing Competition and exposes three independent tuning parameters: time cost (iteration count), memory cost (KB of RAM per hash), and parallelism (lanes). The `id` variant combines the side-channel-resistant Argon2i with the GPU-hostile Argon2d, giving you the best of both. The recommended 2026 starting point for online authentication is `t=2, m=19MiB, p=1`, raising memory until a single verify takes ≈50-100 ms on production hardware.

Recommended uses

  • ·Password hashing for all new designs
  • ·Key derivation from low-entropy secrets

Known attacks / caveats

  • ·None practical.

Designed by

Biryukov, Dinu, Khovratovich, published 2015.

Try it in the password-hash demo →

Deep dive on guptadeepak.com

The Complete Guide to Password Hashing: Argon2 vs Bcrypt vs Scrypt vs PBKDF2 (2026)

The deep-dive on which password-hashing function to pick and how to tune it.

Frequently asked questions

Is Argon2id secure in 2026?
Yes. Argon2id has no practical breaks as of 2026, and no attack better than brute force is known against it.
What is Argon2id used for?
Password hashing for all new designs. Key derivation from low-entropy secrets.
How should Argon2id output be stored?
Argon2id produces a 256-bit derived key, but you do not store that on its own. The output goes in a modular crypt format string that also carries the salt and the cost parameters, so a future verify knows how the stored value was produced. Never store a bare digest for a password.
Can Argon2id be used to hash passwords?
Yes. Argon2id is a password hashing function, designed to be deliberately slow and tuned through cost parameters so that an attacker who steals the database cannot test candidate passwords cheaply.
Who created Argon2id?
Biryukov, Dinu, Khovratovich, published in 2015.