$npx skillfedfor your agent

argon2-cffi

Argon2 for Python

Worth itPyPI CryptographyReleased Jun 202574.4M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — argon2_cffi-25.1.0-py3-none-any.whl
v25.1.0 · released 2025-06-03 · Python >=3.8 · 1 runtime deps: argon2-cffi-bindings

Yes. argon2-cffi is a production-stable, actively maintained library for a critical security task (password hashing). It has no known vulnerabilities, low install friction, permissive licensing, and is widely used (top 1000 on PyPI). Install it if your application needs to hash or verify passwords.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires argon2-cffi-bindings, which is a compiled extension; ensure your platform has a pre-built wheel or a C compiler available.
  • Low install friction with a single compiled dependency (argon2-cffi-bindings).
  • Actively maintained with recent releases; last commit on 2026-08-04 and latest release on 2025-06-03.

License · maintenance · safety

MIT (permissive) — MIT license permits unrestricted use, modification, and distribution in both open-source and commercial contexts with minimal obligations.

last release 2025-06-03 (437 days) · last repo commit 2026-08-04 · 727 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 74,406,319 downloads/mo, #451 on PyPI

Verify before relying

from argon2 import PasswordHasher

ph = PasswordHasher()
hash = ph.hash("correct horse battery staple")
ph.verify(hash, "correct horse battery staple")  # Returns True if match
  • Whether the package is suitable for high-throughput password verification scenarios (performance characteristics not detailed in excerpt).
  • Memory and time cost parameters and their recommended tuning for different threat models.
Same gist for agents: .md · .json

What it is and what it does

argon2-cffi wraps the Argon2 password hashing algorithm—winner of the Password Hashing Competition—in a straightforward Python API. It provides a PasswordHasher class for hashing passwords, verifying them against stored hashes, and checking whether a hash needs to be recomputed with updated parameters. The package depends on argon2-cffi-bindings, a separate low-level CFFI binding to the reference Argon2 implementation.

The library is designed for applications that need to store and validate user passwords securely. It handles the complexity of Argon2's tuning parameters (memory, time, parallelism) internally, exposing sensible defaults while allowing customization. It supports both string and bytes input and works across macOS, Windows, and POSIX systems on current Python versions.

Use it for

  • Hash and verify user passwords during authentication in web applications or services.
  • Migrate legacy password hashes to Argon2 by checking if existing hashes need rehashing with updated parameters.
  • Implement secure password storage in command-line tools or desktop applications.
  • Build authentication systems that comply with modern password security standards.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

argon2-cffi is a production-stable, actively maintained library for a critical security task (password hashing). It has no known vulnerabilities, low install friction, permissive licensing, and is widely used (top 1000 on PyPI). Install it if your application needs to hash or verify passwords.

Install

argon2-cffi on PyPI

Before you install

Low install friction with a single compiled dependency (argon2-cffi-bindings). Actively maintained with recent releases; last commit on 2026-08-04 and latest release on 2025-06-03. Supports current Python versions (3.8 through 3.14) and runs on CPython and PyPy.

Requires argon2-cffi-bindings, which is a compiled extension; ensure your platform has a pre-built wheel or a C compiler available.

License in practice

MIT license permits unrestricted use, modification, and distribution in both open-source and commercial contexts with minimal obligations.

Quickstart

from argon2 import PasswordHasher

ph = PasswordHasher()
hash = ph.hash("correct horse battery staple")
ph.verify(hash, "correct horse battery staple")  # Returns True if match

Verify before relying

  • Whether the package is suitable for high-throughput password verification scenarios (performance characteristics not detailed in excerpt).
  • Memory and time cost parameters and their recommended tuning for different threat models.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.8
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
argon2-cffi-bindings
MaintenanceActively maintained 437 days since the last release
Last repo commit
First released
Downloads74,406,319 / month, #451 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableOperating System :: MacOS :: MacOS XOperating System :: Microsoft :: WindowsOperating System :: POSIXProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Security :: CryptographyTyping :: Typed

Evidence: argon2_cffi-25.1.0-py3-none-any.whl

Tags

Capabilities
password hashing argon2secure password verificationargon2 python librarypassword hash verificationmodern password hashingargon2id password hasherpassword security python
Topics
password-securitycryptography
PyPI keywords
hashhashingpasswordsecurity

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “secure password verification”

  • argon2-cffiProvides a simple Python interface to Argon2, a modern password…
  • pwdlibProvides a modern, easy-to-use wrapper for hashing and verifying…
  • bcryptbcrypt provides modern password hashing using the bcrypt algorithm,…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also altcha · argon2-cffi-bindings · pwdlib · passlib · libpass · keyrings.cryptfile · pyscrypt · bcrypt · murmurhash · siphash