passwordHashGenerate

Creates a secure, salted password hash with Argon2 (default, the Argon2id variant), BCrypt or SCrypt. The returned string embeds the algorithm, its cost parameters and the salt, so passwordHashVerify() can check a password against it without further information.

passwordHashGenerate(password [, algorithm] [, options]) → returns string

This function requires Adobe ColdFusion 2025 and up.  Not supported on Lucee, etc.

Argument Reference

password string
Required

The plaintext password to hash.

algorithm string
Default: Argon2

The hashing algorithm.
Values:
  • Argon2
  • BCrypt
  • SCrypt

options struct

Algorithm-specific settings; secure defaults are used when omitted.
Argon2: SALTLENGTH (16), HASHLENGTH (32), PARALLEL (1), MEMORYCOST in KB (4096), CPUCOST (3).
BCrypt: ROUNDS (10), VERSION ("$2a", also "$2b" or "$2y").
SCrypt: SALTLENGTH (16), KEYLENGTH (32), PARALLEL (1), MEMORYCOST (8), CPUCOST (16384).

Compatibility

ColdFusion:

Version 2025+ Introduced in ColdFusion 2025 Update 8. Replaces the deprecated generateBCryptHash() and generateSCryptHash().

Links more information about passwordHashGenerate

Examples
Sample code invoking the passwordHashGenerate function

Every call produces a different hash because a random salt is generated.

hash = passwordHashGenerate("userPassword123");
writeOutput(hash);

Expected Result: $argon2id$v=19$m=4096,t=3,p=1$cGZyNTFaNDNPaEs1TUt4Sw$CVGQlN+9KRV85Q2jOIVfmw

Raises the memory cost to 64 MB.

hash = passwordHashGenerate("userPassword123", "Argon2", {
	SALTLENGTH: 16,
	HASHLENGTH: 32,
	PARALLEL: 1,
	MEMORYCOST: 65536,
	CPUCOST: 3
});

Selects another algorithm through the second argument.

hash = passwordHashGenerate("userPassword123", "BCrypt");

Signup for cfbreak to stay updated on the latest news from the ColdFusion / CFML community. One email, every friday.

Fork me on GitHub