AxilJS Password Hashing with scrypt
Securely hash and verify passwords in TypeScript and Node.js with AxilJS using the memory-hard scrypt algorithm, unique salts, and constant-time comparison.
Password Hashing
AxilJS provides hashPassword() and verifyPassword() for securely hashing and verifying passwords in TypeScript and Node.js applications.
The implementation uses Node.js's built-in scrypt algorithm, providing memory-hard password hashing without requiring an external bcrypt dependency.
Hash a Password
Use hashPassword() to generate a secure password hash.
The original password should not be stored in your database. Store the generated hash instead.
Verify a Password
Use verifyPassword() to compare a plaintext password against a previously generated hash.
The function returns whether the supplied password matches the stored password hash.
A typical authentication flow is:
scrypt Password Hashing
AxilJS uses Node.js's built-in scrypt implementation for password hashing.
The hashing configuration includes:
- scrypt — memory-hard password derivation algorithm.
- 32-byte salt — a unique salt used during password hashing.
- 64-byte derived key — the generated password key length.
- Constant-time comparison — used when verifying password hashes.
These properties make the password hashing implementation suitable for protecting stored user credentials.
Why scrypt?
scrypt is designed to be computationally and memory intensive, making large-scale password guessing more expensive.
Because AxilJS uses Node.js's built-in scrypt implementation, you do not need to add a separate bcrypt package just to hash and verify passwords.
Password Security
Never store plaintext passwords in your database.
Store the value returned by hashPassword() and use verifyPassword() during authentication.
Do not log passwords or expose password hashes through API responses.
The password verification process uses constant-time comparison to reduce timing-attack risks.
Warning
Never store or log plaintext passwords. Store the generated password hash and verify credentials with verifyPassword().