Authentication

AxilJS Password Hashing with scrypt

Securely hash and verify passwords in TypeScript and Node.js with AxilJS using the memory-hard scrypt algorithm, unique salts, and constant-time comparison.

2 min readDocumentationEdit this page

Password Hashing

AxilJS provides hashPassword() and verifyPassword() for securely hashing and verifying passwords in TypeScript and Node.js applications.

The implementation uses Node.js's built-in scrypt algorithm, providing memory-hard password hashing without requiring an external bcrypt dependency.

Hash a Password

Use hashPassword() to generate a secure password hash.

typescript
import {
  hashPassword,
  verifyPassword
} from '@axiljs/auth'
 
const hashed = await hashPassword('password123')

The original password should not be stored in your database. Store the generated hash instead.

Verify a Password

Use verifyPassword() to compare a plaintext password against a previously generated hash.

typescript
const valid = await verifyPassword(
  'password123',
  hashed
)

The function returns whether the supplied password matches the stored password hash.

A typical authentication flow is:

text
User Password
      │
      ▼
hashPassword()
      │
      ▼
Password Hash
      │
      ▼
     Database
      │
      │
Login Attempt
      │
      ▼
verifyPassword()
      │
      ▼
 Valid / Invalid

scrypt Password Hashing

AxilJS uses Node.js's built-in scrypt implementation for password hashing.

The hashing configuration includes:

  • scrypt — memory-hard password derivation algorithm.
  • 32-byte salt — a unique salt used during password hashing.
  • 64-byte derived key — the generated password key length.
  • Constant-time comparison — used when verifying password hashes.

These properties make the password hashing implementation suitable for protecting stored user credentials.

Why scrypt?

scrypt is designed to be computationally and memory intensive, making large-scale password guessing more expensive.

Because AxilJS uses Node.js's built-in scrypt implementation, you do not need to add a separate bcrypt package just to hash and verify passwords.

typescript
const hashed = await hashPassword('password123')
 
const valid = await verifyPassword(
  'password123',
  hashed
)
 
if (valid) {
  // Password is valid
}

Password Security

Never store plaintext passwords in your database.

Store the value returned by hashPassword() and use verifyPassword() during authentication.

Do not log passwords or expose password hashes through API responses.

The password verification process uses constant-time comparison to reduce timing-attack risks.

Warning

Never store or log plaintext passwords. Store the generated password hash and verify credentials with verifyPassword().

Help improve the documentation

AxilJS is open source and documentation improvements are welcome.

AxilJS DocumentationMIT License · Built by SyntaxilitY