NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #375 most downloaded on PyPI
Argon2 for Python
Last release 1 years ago
03 Jun 2025
Ships fairly regularly
a new release about every 7 months
Nearly every release is documented
notes for 17 of 17 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
18 releases · first in 2015
This release is mostly about smoothing out packaging metadata and improve support for Pyodide / WebAssembly environments.
This release is mostly about smoothing out packaging metadata and improve support for Pyodide / WebAssembly environments.
Full changelog below!
This release would not be possible without my generous sponsors! Thank you to all of you making sustainable maintenance possible! If you would like to join them, go to https://github.com/sponsors/hynek and check out the sweet perks!
Variomedia AG (@variomedia), Tidelift (@tidelift), Klaviyo (@klaviyo), Privacy Solutions GmbH (@privacy-solutions), FilePreviews (@filepreviews), Doist (@Doist), nate nowack (@zzstoatzz), Daniel Fortunov (@asqui), and Kevin P. Fleming (@kpfleming).
Buttondown (@buttondown), Christopher Dignam (@chdsbd), Magnus Watn (@magnuswatn), David Cramer (@dcramer), Jesse Snyder (@jessesnyder), Rivo Laks (@rivol), Polar (@polarsource), Mike Fiedler (@miketheman), Duncan Hill (@cricalix), Colin Marquardt (@cmarqu), Pieter Swinkels (@swinkels), Nick Libertini (@libertininick), Brian M. Dennis (@crossjam), Moving Content AG (@moving-content), ProteinQure (@ProteinQure), The Westervelt Company (@westerveltco), Sławomir Ehlert (@slafs), Mostafa Khalil (@khadrawy), Filip Mularczyk (@mukiblejlok), Thomas Klinger (@thmsklngr), Andreas Poehlmann (@ap--), August Trapper Bigelow (@atbigelow), Carlton Gibson (@carltongibson), and Roboflow (@roboflow).
Not to forget 14 more amazing humans who chose to be generous but anonymous!
argon2.PasswordHasher.check_needs_rehash() now also accepts bytes like the rest of the API. #174
Improved parameter compatibility handling for Pyodide / WebAssembly environments. #190
This release contains contributions from @alarmfox, @hynek, @isidroas, @ngoldbaum, @peterc-s, and @twm.
You can verify this release's artifact attestions using GitHub's CLI tool by downloading the sdist and wheel from PyPI and running:
$ gh attestation verify --owner hynek argon2-cffi-25.1.0.tar.gzand
$ gh attestation verify --owner hynek argon2-cffi-25.1.0-py3-none-any.whlOne column per quarter.
The InvalidHash exception is deprecated in favor of InvalidHashError . No plans for removal currently exist and the names can (but shouldn't) be used…
The only new feature is the possibility to pass an own salt to argon2.PasswordHasher.hash(), however a lot has changed around documentation and packaging to make argon2-cffi maintainable in the future.
This release would not be possible without my generous sponsors! Thank you to all of you making sustainable maintenance possible! If you would like to join them, go to https://github.com/sponsors/hynek and check out the sweet perks!
Variomedia AG (@variomedia), Tidelift (@tidelift), Sentry (@getsentry), HiredScore (@HiredScore), FilePreviews (@filepreviews), Daniel Fortunov (@asqui), and Kevin P. Fleming (@kpfleming).
Adam Hill (@adamghill), Dan Groshev (@si14), Magnus Watn (@magnuswatn), David Cramer (@dcramer), Moving Content AG (@moving-content), Stein Magnus Jodal (@jodal), ProteinQure (@ProteinQure), Jesse Snyder (@jessesnyder), Rivo Laks (@rivol), Tom Ballinger (@thomasballinger), Ionel Cristian Mărieș (@ionelmc), The Westervelt Company (@westerveltco), Philippe Galvan (@PhilippeGalvan), Birk Jernström (@birkjernstrom), Tim Schilling (@tim-schilling), Chris Withers (@cjw296), Christopher Dignam (@chdsbd), and Stefan Hagen (@sthagen).
Not to forget 3 more amazing humans who chose to be generous but anonymous!
The InvalidHash exception is deprecated in favor of InvalidHashError. No plans for removal currently exist and the names can (but shouldn't) be used interchangeably.
argon2.hash_password(), argon2.hash_password_raw(), and argon2.verify_password() that have been soft-deprecated since 2016 are now hard-deprecated. They now raise DeprecationWarnings and will be removed in 2024.
Official support for Python 3.11 and 3.12. No code changes were necessary.
argon2.exceptions.InvalidHashError as a replacement for InvalidHash.
salt parameter to argon2.PasswordHasher.hash() to allow for custom salts. This is only useful for specialized use-cases -- leave it on None unless you know exactly what you are doing. #153
While the last release added type hints, the fact that it's been misssing a py.typed file made Mypy ignore them. #113
py.typed file made Mypy ignore them.py.typed file made Mypy ignore them.
#113Pre-compiled wheels for most relevant platforms (yes, including ARM !)
Python 3.5 is not supported anymore.
The CFFI bindings have been extracted into a separate project: argon2-cffi-bindings This makes argon2-cffi a Python-only project und should make it easier to contribute to and have more frequent releases with high-level features.
This change is breaking for users who want to use a system-wide installation of Argon2 instead of our vendored code, because the argument to the --no-binary argument changed. Please refer to the installation guide.
Thanks to lots of work within argon2-cffi-bindings, there're pre-compiled wheels for many new platforms. Including:
universal2amd64 and arm64i686, amd64, and arm64We hope to provide wheels for Windows on arm64 soon, but are waiting for GitHub Actions to support that.
argon2.Parameters.from_parameters() together with the argon2.profiles module that offers easy access to the RFC-recommended configuration parameters and then some. #101 #110
The CLI interface now has a --profile option that takes any name from argon2.profiles.
Types! argon2-cffi is now fully typed. #112
argon2.PasswordHasher now uses the RFC 9106 low-memory profile by default. The old defaults are available as argon2.profiles.PRE_21_2.Microsoft stopped providing the necessary SDKs to ship Python 2.7 wheels and currenly the downloads amount to 0.09%. Therefore we have decided that Py
Vendoring Argon2 @ 62358ba (20190702)
Microsoft stopped providing the necessary SDKs to ship Python 2.7 wheels and currenly the downloads amount to 0.09%. Therefore we have decided that Python 2.7 is not supported anymore.
none
There are indeed no changes whatsoever to the code of argon2-cffi. The Argon2 project also hasn't tagged a new release since July 2019. There also don't seem to be any important pending fixes.
This release is mainly about improving the way binary wheels are built (abi3 on all platforms).
Vendoring Argon2 @ 62358ba (20190702)
There are indeed no changes whatsoever to the code of argon2-cffi. The Argon2 project also hasn't tagged a new release since July 2019. There also don't seem to be any important pending fixes.
This release is mainly about improving the way binary wheels are built (abi3 on all platforms).
It is now possible to manually override the detection of SSE2 using the ARGON2_CFFI_USE_SSE2 environment variable.
Vendoring Argon2 @ 62358ba (20190702)
ARGON2_CFFI_USE_SSE2 environment variable.Python 3.4 is not supported anymore. It has been unsupported by the Python core team for a while now and its PyPI downloads are negligible.
Vendoring Argon2 @ 62358ba (20190702)
Python 3.4 is not supported anymore. It has been unsupported by the Python core team for a while now and its PyPI downloads are negligible.
It's very unlikely that argon2-cffi will break under 3.4 anytime soon, but we don't test it and don't ship binary wheels for it anymore.
enum34 is now protected using a PEP 508 marker.
This fixes problems when the sdist is handled by a different interpreter version than the one running it.
#48Added support for Argon2 v1.2 hashes in argon2.extract_parameters().
Vendoring Argon2 @ 670229c (20171227)
argon2.extract_parameters().argon2.PasswordHasher's hash type is configurable now.
The hash type for argon2.PasswordHasher is Argon2id now.
Vendoring Argon2 @ 670229c (20171227)
The hash type for argon2.PasswordHasher is Argon2id now.
This decision has been made based on the recommendations in the latest Argon2 RFC draft. #33 #34
Some of the hash parameters have been made stricter to be closer to said recommendations. The current goal for a hash verification times is around 50ms. #41
To make the change of hash type backward compatible, argon2.PasswordHasher.verify() now determines the type of the hash and verifies it accordingly.
To allow for bespoke decisions about upgrading Argon2 parameters, it's now possible to extract them from a hash via the argon2.extract_parameters() function.
#41
Additionally argon2.PasswordHasher now has a check_needs_rehash() method that allows to verify whether a hash has been created with the instance's parameters or whether it should be rehashed.
#41
It is now possible to use the *argon2-cffi* bindings against an Argon2 library that is provided by the system.
Vendoring Argon2 @ 670229c (20171227)
Vendoring Argon2 @ 1c4fc41f81f358283755eea88d4ecd05e43b7fd3
Vendoring Argon2 @ 1c4fc41f81f358283755eea88d4ecd05e43b7fd3 (20161029)
Vendoring Argon2 @ 4844d2fee15d44cb19296ddf36029326d17c5aa3
Vendoring Argon2 @ 4844d2fee15d44cb19296ddf36029326d17c5aa3
Vendoring Argon2 @ 00aaa6604501fade85853a4b2f5695611ff6e7c5.
Vendoring Argon2 @ 00aaa6604501fade85853a4b2f5695611ff6e7c5.
VerifyMismatchError that is raised if verification fails only because of a password/hash mismatch.
It's a subclass of VerificationError therefore this change is completely backwards-compatible.Python 3.3 and 2.6 aren't supported anymore. They may work by chance but any support to them has been ceased.
The last Python 2.6 release was on October 29, 2013 and isn't supported by the CPython core team anymore. Major Python packages like Django and Twisted dropped Python 2.6 a while ago already.
Python 3.3 never had a significant user base and wasn't part of any distribution's LTS release.
Vendoring Argon2 @ 421dafd2a8af5cbb215e16da5953663eb101d139.
Vendoring Argon2 @ 421dafd2a8af5cbb215e16da5953663eb101d139.
hash_password(), hash_password_raw(), and verify_password() should not be used anymore.
For hashing passwords, use the new argon2.PasswordHasher.
If you want to implement your own higher-level abstractions, use the new low-level APIs hash_secret(), hash_secret_raw(), and verify_secret() from the argon2.low_level module.
If you want to go really low-level, core() is for you.
The old functions will not raise any warnings though and there are no immediate plans to remove them.argon2.PasswordHasher.
A higher-level class specifically for hashing passwords that also works on Unicode strings.argon2.low_level module with low-level API bindings for building own high-level abstractions.Vendoring Argon2 @ 4fe0d8cda37691228dd5a96a310be57369403a4b.
Vendoring Argon2 @ 4fe0d8cda37691228dd5a96a310be57369403a4b.
Vendoring Argon2 @ 4fe0d8cda37691228dd5a96a310be57369403a4b.
argon2 on x86 architectures.verify_password() doesn't guess the hash type if passed None anymore.
Supporting this resulted in measurable overhead (~0.6ms vs 0.8ms on my notebook) since it had to happen in Python.
That means that naïve usage of the API would give attackers an edge.
The new behavior is that it has the same default value as hash_password() such that verify_password(hash_password(b"password"), b"password") still works.Vendoring Argon2 @ 4fe0d8cda37691228dd5a96a310be57369403a4b.
Vendoring Argon2 @ 4fe0d8cda37691228dd5a96a310be57369403a4b.
Your coding agent can read these notes before it upgrades. Set up the MCP server →