argon2

A pure-Rust implementation of the Argon2 password hashing function

Library
Cargo
v0.6.0
909 stars
MIT OR Apache-2.0

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
57 /100 Fair
Development Activity 64
Maintenance 16
Community 60
Maturity 60
Momentum 28

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
81 /100 Excellent
Architecture 85
Code Quality 88
Innovation 80
Learning Curve 70

argon2 is a pure-Rust implementation of Argon2, the memory-hard password hashing function that won the Password Hashing Competition in 2015. It implements all three algorithmic variants — Argon2d (GPU-cracking resistant), Argon2i (side-channel resistant), and Argon2id (the recommended hybrid default) — and integrates with the RustCrypto password-hash crate for PHC string encoding/decoding and trait-based password verification.

The crate is part of the RustCrypto password-hashes workspace, which also houses PBKDF2, scrypt, bcrypt-pbkdf, Balloon hashing, SHA-crypt, and yescrypt implementations sharing a common PasswordVerifier/PasswordHash (PHC string) interface. It supports no_std environments (including without alloc), making it usable in embedded targets as well as standard server-side authentication code.

What You Get

  • All three Argon2 variants (Argon2d, Argon2i, and the default Argon2id hybrid)
  • Optional integration with the password-hash crate for PHC string encoding/parsing and a common PasswordVerifier trait shared with pbkdf2, scrypt, and other RustCrypto hashers
  • no_std support, including alloc-free configurations for embedded/constrained targets
  • Optional parallel feature (via rayon) for multi-threaded hashing and a zeroize feature for secure memory wiping of sensitive buffers
  • Configurable Params for memory cost, time cost, and parallelism tuning per OWASP recommendations

Common Use Cases

  • Hashing and verifying user passwords for authentication in a Rust web service or CLI tool
  • Building a multi-algorithm password verifier that can check hashes produced by Argon2, PBKDF2, or scrypt against a single PHC-format string
  • Deriving encryption keys from a low-entropy passphrase (e.g. for at-rest file/database encryption) using Argon2’s memory-hard KDF properties
  • Embedded or constrained targets that need password/key hashing without a standard allocator (no_std, no-alloc builds)

Under The Hood

Architecture: The crate is organized around algorithm.rs (Argon2 core: block filling, mixing, and the d/i/id variant dispatch), block.rs (the 1KB Argon2 memory block type and operations over it), memory.rs (the working-memory matrix the algorithm iterates over), blake2b_long.rs (the variable-output Blake2b hash used internally by Argon2), params.rs (memory/time/parallelism cost parameters and validation), and error.rs/version.rs; lib.rs ties these into the public Argon2 struct implementing the optional password-hash crate’s PasswordHasher/PasswordVerifier traits. Tech Stack: Rust 2024 edition (MSRV 1.85), no_std-first with alloc as an additive feature; depends on base64ct (constant-time base64 for PHC strings) and blake2 for the internal hash primitive, with optional rayon (parallel feature) and zeroize (secure memory wiping) as opt-in features. Code Quality: Ships an extensive [lints.clippy]/[lints.rust] block enforcing missing_docs, unwrap_used warnings, cast-safety lints, and undocumented-unsafe-block checks — a notably strict lint posture for a security-sensitive crate — plus a tests/ directory with known-answer vectors; CI badges reference a dedicated argon2.yml workflow. API Design: The crate offers both a minimal low-level API (Argon2::new(...).hash_password(...)) and, through the shared password-hash trait objects, a pluggable multi-algorithm verifier pattern (as shown in the repo’s own README) that lets callers check a PHC hash string against Argon2, PBKDF2, or scrypt without knowing in advance which algorithm produced it — a deliberate ergonomic win for migrating between hashing schemes.

Used by 16 apps in this directory

Dart
74%
AGPL 3.0

AppFlowy

AI Assistants · Collaboration · Productivity

76,967

The open-source AI workspace that puts your data, your rules — with local LLMs, CRDT collaboration, and full self-hosting built in.

View details
66
Repo Health
81
Technical
67
Dependency
Built with
Dart 74%
Rust 24%
Updated 1 weeks ago
TypeScript
80%
GPL 3.0

Bramble

Authentication · Password Manager · Security

399

Local-first, end-to-end encrypted password manager that syncs your vault directly between your own devices over a private peer-to-peer mesh — no server, no account, no cloud in the middle.

View details
75
Repo Health
84
Technical
68
Dependency
Built with
TypeScript 80%
Updated 5 days ago
Rust
52%
Other

hoodik

File Storage · Security

1,484

Self-hosted, end-to-end encrypted cloud storage with browser-based encryption and S3-compatible storage support

View details
79
Repo Health
71
Technical
63
Dependency
Built with
Rust 52%
TypeScript 33%
Vue 14%
Updated 1 weeks ago
Rust
37%
Other

Hook0

Devops

1,491

Open-source Webhooks-as-a-Service: deliver events to your users with auto-retry, signed payloads, and a real-time subscriber dashboard — all without building the infrastructure yourself.

View details
82
Repo Health
82
Technical
69
Dependency
Built with
Rust 37%
TypeScript 12%
Updated 1 weeks ago
Rust
47%
MIT

Kuku

Note Taking

225

A local-first, open-source Markdown knowledge workspace for macOS — plain files, personal wiki and Second Brain workflows, AI-assisted diffs, and encrypted sync, built as an Obsidian alternative.

View details
52
Repo Health
67
Technical
67
Dependency
Built with
Rust 47%
TypeScript 40%
Updated 3 weeks ago
JavaScript
55%
Other

Lokus

Knowledge Management · Note Taking

802

Local-first note-taking with graph view, canvas & AI plugins—your Markdown files, zero telemetry, blazing-fast Rust performance.

View details
78
Repo Health
75
Technical
65
Dependency
Built with
JavaScript 55%
HTML 21%
Rust 12%
Updated 1 months ago
Rust
71%
Apache 2.0

mesh-llm

AI Agents · AI Development

3,463

Mesh LLM pools GPUs and memory across every machine you own into one OpenAI-compatible API, so agents tap distributed compute instead of a single GPU box or a metered cloud bill.

View details
84
Repo Health
91
Technical
69
Dependency
Built with
Rust 71%
TypeScript 13%
Python 10%
Updated 4 days ago
Rust
95%
Apache 2.0

obscura

AI Agents · Developer Tools

28,080

A lightweight, stealthy headless browser written in Rust — drop-in compatible with Puppeteer and Playwright, built for AI agents and web scraping at scale.

View details
83
Repo Health
79
Technical
72
Dependency
Built with
Rust 95%
Updated 5 days ago
Rust
77%
AGPL 3.0

Spacedrive

Collaboration · File Storage

39,041

One file manager for all your devices and clouds — powered by a Virtual Distributed File System built in Rust.

View details
56
Repo Health
84
Technical
63
Dependency
Built with
Rust 77%
TypeScript 20%
Updated 2 months ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers