Decode.Cryptography 2.0.1

There is a newer version of this package available.
See the version list below for details.
dotnet add package Decode.Cryptography --version 2.0.1
                    
NuGet\Install-Package Decode.Cryptography -Version 2.0.1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Decode.Cryptography" Version="2.0.1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Decode.Cryptography" Version="2.0.1" />
                    
Directory.Packages.props
<PackageReference Include="Decode.Cryptography" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Decode.Cryptography --version 2.0.1
                    
#r "nuget: Decode.Cryptography, 2.0.1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Decode.Cryptography@2.0.1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Decode.Cryptography&version=2.0.1
                    
Install as a Cake Addin
#tool nuget:?package=Decode.Cryptography&version=2.0.1
                    
Install as a Cake Tool

Decode.Cryptography

Modern and secure cryptography utilities for .NET, providing a clean API for common cryptographic operations.

🚀 Features

  • Secure Password Hashing (PBKDF2): Key derivation using HMAC-SHA256, 100,000 iterations by default and overridable per call.
  • Timing Attack Protection: VerifySha256 and VerifyHmacSha256 compare with CryptographicOperations.FixedTimeEquals, and treat malformed input as a failed verification rather than throwing.
  • HMAC: Message authentication using SHA256.
  • SHA256: Standard hashing with support for multiple iterations.
  • HEX & Base64: Conversions built on native .NET primitives (Convert.ToHexString / FromHexString) where the target framework provides them.
  • No MD5/SHA1: Insecure algorithms are not part of the API.

📦 Installation

dotnet add package Decode.Cryptography

📖 Usage

Hashing a Password (PBKDF2)

This is the recommended way to store user passwords.

using Decode.Cryptography;

// Generate a unique salt for the user
string salt = Hash.GenerateSaltToBase64String();

// Hash the password with the salt
string hash = Hash.HashPasswordToBase64String("user-password", salt);

// Store both 'salt' and 'hash' in your database

Defaults are exposed as constants — Hash.DefaultSaltSize (36 bytes), Hash.DefaultHashSize (36 bytes) and Hash.DefaultIterations (100,000).

On the iteration count. 100,000 is the default, not a ceiling — iterations is a parameter on HashPasswordToBase64String. OWASP's current guidance for PBKDF2-HMAC-SHA256 is considerably higher (600,000 at the time of writing). Raising it is a one-line change for new hashes, but it invalidates existing ones unless you store the iteration count alongside the salt and hash, so choose the value deliberately before your first deployment.

Verifying a Password

There is no VerifyPassword helper: re-derive with the stored salt and compare in constant time. Do not compare the Base64 strings with ==, which short-circuits on the first differing character and leaks timing information.

using System.Security.Cryptography;
using Decode.Cryptography;

// storedSalt and storedHash come from your database
string candidate = Hash.HashPasswordToBase64String(attemptedPassword, storedSalt);

bool isValid = CryptographicOperations.FixedTimeEquals(
    Convert.FromBase64String(candidate),
    Convert.FromBase64String(storedHash));

Pass the same iterations and hashSize used when the password was first hashed, if you overrode the defaults.

Renamed in 2.0.0. These were previously DEFAULT_SALT_SIZE, DEFAULT_HASH_SIZE and DEFAULT_ITERATIONS. The values are unchanged; only the names now follow .NET conventions.

Salt generation changed in 2.0.0. GenerateSaltToBase64String used RandomNumberGenerator.GetNonZeroBytes, a legacy PKCS#1 padding helper that never emits 0x00 and therefore narrowed each byte from 256 to 255 possible values. It now uses GetBytes. Existing stored salts and hashes remain valid — nothing needs to be rehashed.

Computing HMAC-SHA256

// hexKey must be a valid hexadecimal string
string hmac = Hash.ComputeHmacSha256ToBase64String(hexKey, "content");

SHA256 Hashing & Verification

Useful for checking file integrity or raw data hashing.

// Generate SHA256 hash as Hex string
string sha256Hex = Hash.ComputeSha256ToHexString("my-content");

// Verify if a content matches a hash (uses Constant-Time comparison)
bool isSha256Valid = Hash.VerifySha256("my-content", sha256Hex);

HMAC-SHA256 Verification

Useful for verifying webhooks or request signatures.

bool isSignatureValid = Hash.VerifyHmacSha256(hexKey, "content", base64HashToVerify);

Array Manipulation

Utilities to combine and split byte arrays/spans efficiently:

byte[] part1 = [0x01, 0x02];
byte[] part2 = [0x03, 0x04];

// Combine arrays
byte[] combined = Utils.CombineArray(part1, part2);

// Split arrays back (splits 'combined' into first 2 bytes and the rest)
Utils.SplitArray(combined, length: 2, out byte[] first, out byte[] second);

HEX Conversions

byte[] data = [0xDE, 0xAD, 0xBE, 0xEF];

// Convert to HEX string
string hex = Utils.ToHexString(data);

// Convert back to byte array
byte[] back = Utils.FromHexString(hex);

🔒 Security Note

  • No MD5/SHA1: Insecure algorithms are not included.
  • Constant-Time Comparison: VerifySha256 and VerifyHmacSha256 use FixedTimeEquals, so they do not leak information through timing. Password verification is your code's responsibility — follow the recipe above.
  • Iteration Count: 100,000 by default, which raises the cost of GPU brute-force considerably over a bare hash, but sits below OWASP's current PBKDF2-HMAC-SHA256 recommendation. Set iterations explicitly if you need to match it.
  • Not a password-storage framework: there is no built-in rehash-on-login, no versioned hash format and no iteration count embedded in the output. If you need those, store the parameters yourself alongside the salt and hash.

📄 License

MIT License.

Product Compatible and additional computed target framework versions.
.NET net5.0 was computed.  net5.0-windows was computed.  net6.0 was computed.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 is compatible.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
.NET Core netcoreapp3.0 was computed.  netcoreapp3.1 was computed. 
.NET Standard netstandard2.1 is compatible. 
MonoAndroid monoandroid was computed. 
MonoMac monomac was computed. 
MonoTouch monotouch was computed. 
Tizen tizen60 was computed. 
Xamarin.iOS xamarinios was computed. 
Xamarin.Mac xamarinmac was computed. 
Xamarin.TVOS xamarintvos was computed. 
Xamarin.WatchOS xamarinwatchos was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • .NETStandard 2.1

    • No dependencies.
  • net8.0

    • No dependencies.
  • net9.0

    • No dependencies.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
3.0.0 87 9/14/2026
2.1.0 87 9/13/2026
2.0.2 76 9/13/2026
2.0.1 81 9/13/2026
2.0.0 114 7/28/2026
1.0.3 131 6/19/2026
1.0.2 130 5/26/2026
1.0.1 115 4/26/2026