PHP password_hash() Function
PHP Password Hashing Algorithms
The password_hash() function is used to create a hash of a password.
PHP Version Requirements: PHP 5 >= 5.5.0, PHP 7
Syntax
string password_hash ( string $password , int $algo [, array $options ] )
password_hash() uses a sufficiently strong one-way hashing algorithm to create a hash of a password. password_hash() is compatible with crypt(). Therefore, password hashes created by crypt() can also be used with password_hash().
Currently supported algorithms:
-
PASSWORD_DEFAULT- Uses the bcrypt algorithm (default in PHP 5.5.0). Note that this constant will change as PHP adds newer, stronger algorithms. Therefore, the length of the result generated using this constant may change in the future. Therefore, the column in the database that stores the result can exceed 60 characters (preferably 255 characters). -
PASSWORD_BCRYPT- UseCRYPT_BLOWFISHthe algorithm to create a hash. This will produce a hash compatible with using "$2y$" prefix.crypt()The result will be a 60-character string, or FALSE on failure.FALSE。 -
PASSWORD_ARGON2I- Use the Argon2 hashing algorithm to create a hash.
Options supported by PASSWORD_BCRYPT:
-
salt (string) - Manually provide a salt for hashing the password. This avoids automatically generating a salt.
If this value is omitted, password_hash() will automatically generate a random salt for each password hash. This is an intentional mode of operation.
Note: The salt option has been deprecated as of PHP 7.0.0. It is now better to simply use the default generated salt.
-
cost (integer) - Represents the cost used by the algorithm. Examples of cost values can be found on the crypt() page.
When omitted, the default value is 10. This cost is a good baseline, but you may increase this value depending on your hardware.
Options supported by PASSWORD_ARGON2I:
-
memory_cost (integer) - The maximum memory (in bytes) to be used when calculating the Argon2 hash. Default value:
PASSWORD_ARGON2_DEFAULT_MEMORY_COST。 -
time_cost (integer) - The maximum time to be used when calculating the Argon2 hash. Default value:
PASSWORD_ARGON2_DEFAULT_TIME_COST。 -
threads (integer) - The maximum number of threads to be used when calculating the Argon2 hash. Default value:
PASSWORD_ARGON2_DEFAULT_THREADS。
Parameter description:
password: A hash value created by password_hash().
algo: A password algorithm constant used to indicate the algorithm when hashing the password.
options: An associative array containing options. Currently two options are supported: salt, the salt (interference string) added when hashing the password, and cost, used to indicate the number of recursive layers of the algorithm. Examples of these two values can be found on the crypt() page.
When omitted, a random salt and the default cost will be used.
Return Value
Returns the hashed password, or FALSE on failure.
Examples
Example 1
The output is:
$2y$10$.vGA1O9wmRjrwAVXD98HNOgsNpDczlqm3Jq7KnEd1rVAGv3Fykk1a
Example 2
The output is:
$2y$12$QjSH496pcT5CEbzjD/vtVeH03tfHKFy36d4J0Ltp3lRtee9HDxY3K
Example 3
Example of manually setting the salt value
The output is:
$2y$11$q5MkhSBtlsJcNEVsYh64a.aCluzHnGog7TQAKVmQwO9C8xb.t89F.
Example 4
Example of password_hash() for finding the optimal cost
The output is:
Appropriate Cost Found: 10
Example 5
Example using Argon2:
The output is:
Argon2 hash: $argon2i$v=19$m=1024,t=2,p=2$YzJBSzV4TUhkMzc3d3laeg$zqU/1IN0/AogfP4cmSJI1vc8lpXRW9/S0sYY2i2jHT0Other Extensions