Cisco IOS and IOS XE scrypt format

Cisco Type 9 Password Generator

Create a salted $9$ scrypt hash for compatible Cisco configurations. The password, salt, and hash stay in this browser tab.

Generate a Cisco Type 9 hash

Use a new password for this device. Confirm Type 9 support on the exact Cisco platform and release before deploying the result.

Used only to format the username command; it is not part of the hash.
1–25 printable ASCII characters for broad IOS and IOS XE command compatibility.

Scrypt N=16384, r=1, p=132-byte derived keyReady
Hashed locallyThe plaintext password is processed only in this tab. The page does not submit it to a remote hashing service or save it in browser storage.

What Cisco Type 9 means

Type 9 is Cisco's scrypt-based one-way password-hash format. A result starts with $9$, includes a fresh 14-character salt, and ends with the encoded derived key. It is not reversible encryption and this tool does not decrypt existing hashes.

How to use the generated value

The tool formats both username … secret 9 … and enable secret 9 … examples. Those commands tell a compatible device that the supplied value is already hashed. Never place cleartext after the 9 type marker. Review the pending configuration and test access in a recoverable session before saving it.

Why the same password produces different hashes

Every generation uses a new cryptographically random salt. Two Type 9 hashes can therefore differ even when the plaintext is identical. The salt is stored inside the hash and is not secret; it prevents identical passwords from producing identical stored values.

Compatibility varies by Cisco product

Cisco IOS, IOS XE, NX-OS, ASA, and other Cisco product families do not necessarily accept the same commands or password types. Type 9 support also varies by software release and feature. Confirm the syntax and supported secret types in the configuration guide for the exact device before changing authentication.

Protect the output and the configuration

Scrypt is intentionally expensive to guess, but a weak password can still be cracked offline if a configuration is exposed. Use a unique random password, restrict access to configuration backups, avoid logging the cleartext, and rotate the secret after suspected disclosure.

Implementation and validation

This browser implementation uses the Cisco Type 9 parameters N=16384, r=1, p=1 with a 32-byte derived key and Cisco's Base64 alphabet. Its automated test suite checks the published Cisco example for plaintext cisco and salt nhEmQVczB7dqsO byte for byte.

References

See Cisco's official security command reference for Type 9 syntax and example output, and Cisco's Protecting Secrets guidance for password-type recommendations.

Related developer tools

Bcrypt generator creates application password hashes in the bcrypt format. Hash generator calculates fast file and text checksums. Random key generator creates raw random bytes for compatible applications.