FusionAuth does not perform Unicode normalization on passwords before hashing.

Passwords are hashed using the raw bytes exactly as received from the client. This means:

If a user sets a password with Unicode characters, those exact byte sequences are hashed Different Unicode representations of visually identical characters (e.g., é as a single composed character U+00E9 vs. e + combining acute accent U+0065 U+0301) will result in different password hashes No normalization forms (NFC, NFD, NFKC, NFKD) are applied

This behavior means you should ensure consistent encoding at the application level if Unicode normalization is important for your use case. The password validation will only succeed if the exact same byte sequence is provided during authentication.

Additional Context

FusionAuth fully supports Unicode characters in passwords, which is recommended for both usability and security reasons. When FusionAuth validates passwords for special characters, it processes them as Unicode strings (using Java's Character.isAlphabetic() and Character.isDigit() methods on 16-bit Unicode values), confirming that passwords are handled as Unicode throughout the system.

There are no inherent limitations on which Unicode characters can be used in passwords stored in FusionAuth, though you can configure password validation rules to enforce specific requirements for your tenant.

Related Documentation Password-Hashing Algorithms - Overview of FusionAuth's password hashing schemes (PBKDF2, Bcrypt, etc.) Custom Password Hashing - Information on implementing custom password hashing schemes Password Validation Rules - API for retrieving and configuring password validation rules Client-side Password Rule Validation - Guide for implementing password validation in your client application Are there any disallowed characters in passwords? - Community discussion confirming no inherent character limitations