Skip to content

Function: deriveMasterKey() ​

deriveMasterKey(password, salt): Promise<SecretBytes>

Defined in: kdf.ts:26

Derives a 32-byte master key from a password with Argon2id (19 MiB memory, 2 passes, 1 lane: the OWASP interactive profile). The result stays in WASM memory as SecretBytes; use deriveKey() on it to obtain purpose-specific subkeys (for example an auth key and a vault key with different info strings).

This is not part of quantum-safe-py (which has no master-password concept), so there is no cross-library compatibility requirement; the parameters are fixed so the same password and salt always give the same key.

Passwords are used as the UTF-8 bytes of the string you pass, with no Unicode normalisation. If users may type the same password in different composed forms, normalise it first (for example password.normalize('NFKC')) and do so consistently everywhere.

The call is CPU- and memory-heavy. It currently runs synchronously on the calling thread inside the returned promise; in a browser, run it in a Web Worker to keep the UI responsive.

Parameters ​

password ​

string | Uint8Array<ArrayBufferLike>

The password (string, or bytes you control and should wipe afterwards).

salt ​

Uint8Array

At least 8 bytes; use 16+ random bytes per user.

Returns ​

Promise<SecretBytes>

Throws ​

for a too-short salt.

Apache-2.0.