Argon2id
Winner of the Password Hashing Competition. Memory-hard, side-channel resistant, three tunable knobs. The 2026 default.
By Deepak Gupta ·
Argon2id is the recommended password-hashing function in OWASP's 2025 cheatsheet, in NIST SP 800-63B, and in essentially every other modern guidance document. It's the winning entry of the 2015 Password Hashing Competition and exposes three independent tuning parameters: time cost (iteration count), memory cost (KB of RAM per hash), and parallelism (lanes). The `id` variant combines the side-channel-resistant Argon2i with the GPU-hostile Argon2d, giving you the best of both. The recommended 2026 starting point for online authentication is `t=2, m=19MiB, p=1`, raising memory until a single verify takes ≈50-100 ms on production hardware.
Recommended uses
- ·Password hashing for all new designs
- ·Key derivation from low-entropy secrets
Known attacks / caveats
- ·None practical.
Designed by
Biryukov, Dinu, Khovratovich, published 2015.
Deep dive on guptadeepak.com
The Complete Guide to Password Hashing: Argon2 vs Bcrypt vs Scrypt vs PBKDF2 (2026)
The deep-dive on which password-hashing function to pick and how to tune it.
Frequently asked questions
- Is Argon2id secure in 2026?
- Yes. Argon2id has no practical breaks as of 2026, and no attack better than brute force is known against it.
- What is Argon2id used for?
- Password hashing for all new designs. Key derivation from low-entropy secrets.
- How should Argon2id output be stored?
- Argon2id produces a 256-bit derived key, but you do not store that on its own. The output goes in a modular crypt format string that also carries the salt and the cost parameters, so a future verify knows how the stored value was produced. Never store a bare digest for a password.
- Can Argon2id be used to hash passwords?
- Yes. Argon2id is a password hashing function, designed to be deliberately slow and tuned through cost parameters so that an attacker who steals the database cannot test candidate passwords cheaply.
- Who created Argon2id?
- Biryukov, Dinu, Khovratovich, published in 2015.