scribase
Security and secretsversion 1.3on by default

pgcrypto

Hashing, password hashing and encryption functions.

What it is for

pgcrypto provides digest and hmac for hashing, crypt with gen_salt for bcrypt password hashes, gen_random_bytes for tokens, and PGP symmetric and public-key encryption. For random UUIDs you no longer need it: gen_random_uuid() is built into Postgres.

Enable it

sql
create extension if not exists pgcrypto with schema extensions;

Example

sql
select encode(digest('hello', 'sha256'), 'hex');

-- bcrypt hash and check
select crypt('correct horse', gen_salt('bf', 10));
select crypt('correct horse', stored_hash) = stored_hash from accounts where id = 1;

select encode(gen_random_bytes(32), 'base64') as token;

Notes

  • On in every project, in the extensions schema. Qualify calls as extensions.crypt(...) if that schema is not on your search_path.

Questions

How do I enable pgcrypto?

Run create extension if not exists pgcrypto with schema extensions; in the SQL editor, or switch it on from the Extensions page in the console. You do not need superuser access.

Which version of pgcrypto is installed?

1.3, on Postgres 17.6, as read from the running engine on 2026-10-08. Check yours with: select extversion from pg_extension where extname = 'pgcrypto';

Upstream project: www.postgresql.org/docs/17/pgcrypto.html

More security and secrets extensions

  • supabase_vault Store secrets encrypted with a key only the server can read.
  • pgaudit Write detailed audit lines for the statements you choose.