FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login

    Does FusionAuth normalize Unicode characters in passwords before hashing?

    Scheduled Pinned Locked Moved Solved
    Frequently Asked Questions (FAQ)
    password unicode security authentication hashing
    1
    2
    54
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FASupportBot
      last edited by dan

      I'm trying to understand how FusionAuth handles Unicode characters in user passwords.From testing, it appears that:

      • Unicode characters are accepted as valid characters in passwords
      • No Unicode normalization occurs before hashing the password

      Can someone confirm whether FusionAuth performs any Unicode normalization (such as NFC, NFD, NFKC, or NFKD) on passwords before hashing them? Or does FusionAuth hash the raw bytes exactly as received?

      This is important for understanding how passwords with visually identical but technically different Unicode representations (e.g., composed vs. decomposed characters) would be handled.

      If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

      1 Reply Last reply Reply Quote 0
      • F
        FASupportBot
        last edited by

        FusionAuth does not perform Unicode normalization on passwords before hashing.

        Passwords are hashed using the raw bytes exactly as received from the client. This means:

        • If a user sets a password with Unicode characters, those exact byte sequences are hashed
        • Different Unicode representations of visually identical characters (e.g., é as a single composed character U+00E9 vs. e + combining acute accent U+0065 U+0301) will result in different password hashes
        • No normalization forms (NFC, NFD, NFKC, NFKD) are applied

        This behavior means you should ensure consistent encoding at the application level if Unicode normalization is important for your use case. The password validation will only succeed if the exact same byte sequence is provided during authentication.

        Additional Context

        FusionAuth fully supports Unicode characters in passwords, which is recommended for both usability and security reasons. When FusionAuth validates passwords for special characters, it processes them as Unicode strings (using Java's Character.isAlphabetic() and Character.isDigit() methods on 16-bit Unicode values), confirming that passwords are handled as Unicode throughout the system.

        There are no inherent limitations on which Unicode characters can be used in passwords stored in FusionAuth, though you can configure password validation rules to enforce specific requirements for your tenant.

        Related Documentation

        • Password-Hashing Algorithms - Overview of FusionAuth's password hashing schemes (PBKDF2, Bcrypt, etc.)
        • Custom Password Hashing - Information on implementing custom password hashing schemes
        • Password Validation Rules - API for retrieving and configuring password validation rules
        • Client-side Password Rule Validation - Guide for implementing password validation in your client application
        • Are there any disallowed characters in passwords? - Community discussion confirming no inherent character limitations

        If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

        1 Reply Last reply Reply Quote 0
        • danD dan has marked this topic as solved
        • danD dan moved this topic from Staged
        • First post
          Last post