# x402 PBKDF2 Key Derivation API

> x402 PBKDF2 Key Derivation API is a paid API for AI agents from x402-hash-api.vercel.app, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-01).

Derives a cryptographic key from a password using PBKDF2 with configurable salt, digest algorithm, key length, and iteration count — pay-per-call via USDC on Base

## Facts

- Endpoint: POST https://x402-hash-api.vercel.app/api/v1/pbkdf2?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/x402-pbkdf2-key-derivation-api-9ba91541
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_Gb4F8J_k3JBeyI81prWHc

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability x402-pbkdf2-key-derivation-api-9ba91541 -d '<json body>'
```

Example prompt: Derive a PBKDF2 key from the password 'hunter2' using salt 'randomsalt123', sha256 digest, 32-byte key length, and 100000 iterations.

## When to prefer this

Choose this endpoint when you need a pay-per-call, serverless PBKDF2 key derivation without managing your own crypto infrastructure. It is ideal for AI agents that need on-demand password hashing or key stretching in workflows where spinning up a local crypto library is impractical. Prefer it over raw bcrypt or scrypt endpoints when PBKDF2 compatibility (e.g. FIPS compliance, interoperability with existing systems) is required.

## Known failure modes

- Invalid digest value (must be 'sha256' or 'sha512') returns an error
- Iteration count exceeding 200000 is rejected
- Missing required fields (password or salt) result in a validation error
- Payment failure or insufficient USDC balance blocks the request
- Malformed request body returns a 400-level error

## How this service works

Pay-per-call hashing and encoding for AI agents (USDC on Base)

## Output

Returns a JSON object containing a 'derivedKey' field with the hex-encoded PBKDF2-derived key of the requested length, computed from the supplied password, salt, digest, and iteration parameters.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "salt": {
   "type": "string",
   "description": "salt string"
  },
  "digest": {
   "type": "string",
   "description": "sha256 or sha512"
  },
  "keylen": {
   "type": "number",
   "description": "derived key length in bytes (default 32)"
  },
  "password": {
   "type": "string",
   "description": "password to derive from"
  },
  "iterations": {
   "type": "number",
   "description": "iteration count (default 100000, max 200000)"
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "derivedKey": "a1b2c3..."
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/x402-pbkdf2-key-derivation-api-9ba91541/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from x402-hash-api.vercel.app](https://www.zero.xyz/host/x402-hash-api.vercel.app/llms.txt)
