What Cisco Type 9 means
Type 9 is Cisco's scrypt-based one-way password-hash format. A result starts with $9$, includes a fresh 14-character salt, and ends with the encoded derived key. It is not reversible encryption and this tool does not decrypt existing hashes.
How to use the generated value
The tool formats both username … secret 9 … and enable secret 9 … examples. Those commands tell a compatible device that the supplied value is already hashed. Never place cleartext after the 9 type marker. Review the pending configuration and test access in a recoverable session before saving it.
Why the same password produces different hashes
Every generation uses a new cryptographically random salt. Two Type 9 hashes can therefore differ even when the plaintext is identical. The salt is stored inside the hash and is not secret; it prevents identical passwords from producing identical stored values.
Compatibility varies by Cisco product
Cisco IOS, IOS XE, NX-OS, ASA, and other Cisco product families do not necessarily accept the same commands or password types. Type 9 support also varies by software release and feature. Confirm the syntax and supported secret types in the configuration guide for the exact device before changing authentication.
Protect the output and the configuration
Scrypt is intentionally expensive to guess, but a weak password can still be cracked offline if a configuration is exposed. Use a unique random password, restrict access to configuration backups, avoid logging the cleartext, and rotate the secret after suspected disclosure.
Implementation and validation
This browser implementation uses the Cisco Type 9 parameters N=16384, r=1, p=1 with a 32-byte derived key and Cisco's Base64 alphabet. Its automated test suite checks the published Cisco example for plaintext cisco and salt nhEmQVczB7dqsO byte for byte.
References
See Cisco's official security command reference for Type 9 syntax and example output, and Cisco's Protecting Secrets guidance for password-type recommendations.
Related developer tools
Bcrypt generator creates application password hashes in the bcrypt format. Hash generator calculates fast file and text checksums. Random key generator creates raw random bytes for compatible applications.