Pepper (Password Hashing)
Field: Security · Also called: password pepper, peppering, site salt
A pepper is a secret value, shared by all stored passwords, that is mixed into password hashing and kept separately from the password database, so a breach of the database alone does not let an attacker test passwords offline.
Pepper and salt
A salt is unique to each password, stored with the hash, and not secret. A pepper is the same for every password, secret, and stored somewhere else. Because a pepper is shared, it does not make identical passwords produce different hashes. That is the salt’s job. The two are used together.
How it is applied
OWASP’s Password Storage Cheat Sheet describes two approaches. The pepper can be added to the password before it is hashed by the password hashing algorithm, or the resulting hash can be hashed again with HMAC, using the pepper as the HMAC key. Either way, the pepper “should be stored separately from the password database.”
NIST SP 800-63B (Revision 4), section 3.1.1.2, recommends the same control without using the word “pepper.” Verifiers “SHOULD perform an additional iteration of a keyed hashing or encryption operation using a secret key known only to the verifier,” and the key “SHALL be stored separately from the hashed passwords,” preferably within a hardware security module or trusted execution environment.
Trade-offs
A pepper cannot be changed without each user’s password. OWASP notes that changing it requires forcing every user whose password was protected by the old pepper to reset it. For the same reason, a lost pepper makes every stored password impossible to verify.
History
The name is a play on salt, since pepper is the seasoning that sits next to salt. Practitioners have also used salt for both the site-wide value and the per-record value, calling the site-wide one a site salt. Really Bad Passwords (with Unsalted Hashes) (Rietta, 2012) recommends that “both a site salt and an account-specific salt should be used.” A site salt serves the role now called a pepper when it is kept secret and stored apart from the password database. NIST SP 800-63B describes the control without using either name.
Sources
- Password Storage Cheat Sheet, OWASP Cheat Sheet Series. Retrieved October 2, 2026.
- NIST SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management, NIST, August 2025. Retrieved October 2, 2026.
See also
Go deeper
Articles
- Really Bad Passwords (with Unsalted Hashes) June 8, 2012