Skip to content

Glossary

Pepper

A pepper is a secret value added to every password before hashing, kept outside the database so a database leak alone does not expose it like a salt would.

A pepper is a secret value mixed into every password before hashing, similar to a salt but with one critical difference: it is the same for every user, and it is never stored alongside the hash. Where a salt sits in the database next to its hash in plain sight, a pepper lives elsewhere entirely — an environment variable, a config file, or a hardware security module — so that stealing the password database does not hand an attacker the pepper too.

That separation is the whole point. If an attacker dumps the database, they get hashes and salts but not the pepper, so they cannot even begin testing guesses correctly until they also compromise the application server or secrets store. A salt alone cannot do this, because it is only designed to defeat rainbow tables and stop identical passwords from matching — it assumes the attacker already has it.

A pepper is a defence-in-depth measure, not a replacement for a slow algorithm. It is typically implemented as an HMAC key applied before (or alongside) a proper password-hashing function such as bcrypt or Argon2; see Argon2 vs bcrypt vs scrypt for picking the underlying KDF a pepper should be layered onto.