<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Does FusionAuth normalize Unicode characters in passwords before hashing?]]></title><description><![CDATA[<p dir="auto">I'm trying to understand how FusionAuth handles Unicode characters in user passwords.From testing, it appears that:</p>
<ul>
<li>Unicode characters are accepted as valid characters in passwords</li>
<li>No Unicode normalization occurs before hashing the password</li>
</ul>
<p dir="auto">Can someone confirm whether FusionAuth performs any Unicode normalization (such as NFC, NFD, NFKC, or NFKD) on passwords before hashing them? Or does FusionAuth hash the raw bytes exactly as received?</p>
<p dir="auto">This is important for understanding how passwords with visually identical but technically different Unicode representations (e.g., composed vs. decomposed characters) would be handled.</p>
]]></description><link>https://fusionauth.io/community/forum/topic/3175/does-fusionauth-normalize-unicode-characters-in-passwords-before-hashing</link><generator>RSS for Node</generator><lastBuildDate>Thu, 01 Oct 2026 03:04:20 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3175.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 30 Sep 2026 19:43:22 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Does FusionAuth normalize Unicode characters in passwords before hashing? on Wed, 30 Sep 2026 19:43:33 GMT]]></title><description><![CDATA[<p dir="auto">FusionAuth does <strong>not</strong> perform Unicode normalization on passwords before hashing.</p>
<p dir="auto">Passwords are hashed using the raw bytes exactly as received from the client. This means:</p>
<ul>
<li>If a user sets a password with Unicode characters, those exact byte sequences are hashed</li>
<li>Different Unicode representations of visually identical characters (e.g., é as a single composed character U+00E9 vs. e + combining acute accent U+0065 U+0301) will result in different password hashes</li>
<li>No normalization forms (NFC, NFD, NFKC, NFKD) are applied</li>
</ul>
<p dir="auto">This behavior means you should ensure consistent encoding at the application level if Unicode normalization is important for your use case. The password validation will only succeed if the exact same byte sequence is provided during authentication.</p>
<h2>Additional Context</h2>
<p dir="auto">FusionAuth fully supports Unicode characters in passwords, which is recommended for both usability and security reasons. When FusionAuth validates passwords for special characters, it processes them as Unicode strings (using Java's <code>Character.isAlphabetic()</code> and <code>Character.isDigit()</code> methods on 16-bit Unicode values), confirming that passwords are handled as Unicode throughout the system.</p>
<p dir="auto">There are no inherent limitations on which Unicode characters can be used in passwords stored in FusionAuth, though you can configure <a href="https://fusionauth.io/docs/apis/tenants/retrieve-the-password-validation-rules" rel="nofollow ugc">password validation rules</a> to enforce specific requirements for your tenant.</p>
<h2>Related Documentation</h2>
<ul>
<li><a href="https://fusionauth.io/docs/reference/password-hashes" rel="nofollow ugc">Password-Hashing Algorithms</a> - Overview of FusionAuth's password hashing schemes (PBKDF2, Bcrypt, etc.)</li>
<li><a href="https://fusionauth.io/docs/extend/code/password-hashes/custom-password-hashing" rel="nofollow ugc">Custom Password Hashing</a> - Information on implementing custom password hashing schemes</li>
<li><a href="https://fusionauth.io/docs/apis/tenants/retrieve-the-password-validation-rules" rel="nofollow ugc">Password Validation Rules</a> - API for retrieving and configuring password validation rules</li>
<li><a href="https://fusionauth.io/docs/customize/look-and-feel/client-side-password-rule-validation" rel="nofollow ugc">Client-side Password Rule Validation</a> - Guide for implementing password validation in your client application</li>
<li><a href="https://fusionauth.io/community/forum/topic/190/are-there-any-disallowed-characters-in-passwords">Are there any disallowed characters in passwords?</a> - Community discussion confirming no inherent character limitations</li>
</ul>
]]></description><link>https://fusionauth.io/community/forum/post/8687</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8687</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Wed, 30 Sep 2026 19:43:33 GMT</pubDate></item></channel></rss>