PWENCODE Procedure

Using Encoded Passwords in SAS Programs

When a password is encoded with PROC PWENCODE, the output string includes a tag that identifies the string as having been encoded. An example of a tag is {sas001}. The tag indicates the encoding method. SAS servers and SAS/ACCESS engines recognize the tag and decode the string before using it. Encoding a password enables you to write SAS programs without having to specify a password in plaintext.

Note: PROC PWENCODE passwords can contain up to a maximum of 512 characters, which include alphanumeric characters, spaces, and special characters. Data set passwords, however, must follow SAS naming rules. For information, see SAS Names in SAS Programmer’s Guide: Essentials.

The encoded password is never written to the SAS log in plain text. Instead, each character of the password is replaced by an X in the SAS log.

Encoding versus Encryption

Encoding techniques disguise passwords and the approach is intended to prevent casual, non-malicious viewing of passwords. With encoding, one character set is translated to another character set through some form of table lookup. SAS001–SAS005 encoding methods are considered encoding methods.

Encryption, by contrast, involves the transformation of data from one form to another through the use of mathematical operations and, usually, a "key" value. Encryption is generally more difficult to break than encoding.

SAS003, SAS004, and SAS005 methods specified in PROC PWENCODE designate encryption techniques that align with industry standards. These options support longer encryption keys (for example, 256-bit). Salting and multiple iterations are provided to the AES encryption algorithm to create passwords that are harder to break.

Encoding methods for PROC PWENCODE are shown in Encoding Methods .

Password protection is an important part of your security strategy, but you should not rely only on password protection for all your data security needs; a determined and knowledgeable attacker can break passwords. Data should also be protected by other security controls such as file system permissions, other access control mechanisms, and encryption of data at rest and in motion.

Encoding Methods

The following encoding methods are supported.

Supported Encoding Methods

Encoding Method

Data Encryption Algorithm Used

Encoded Password/key Description

sas001

None

Uses base64 to encode passwords.

sas002, which can also be specified as sasenc

SASProprietary is included in SAS software.

Uses a 32-bit fixed key.

sas003

AES (Advanced Encryption Standard)

Uses a 256-bit fixed key plus a 16-bit random salt value.

sas004

AES (Advanced Encryption Standard)

Uses a 256-bit fixed key and a 64-bit random salt value.

sas005

AES (Advanced Encryption Standard)

Uses a 256-bit fixed key, a 64-bit random salt value, and is hashed for additional iterations.

The SAS003, SAS004, and SAS005 encoded passwords use AES encryption and a 256-bit fixed key. In addition, a random salt value is applied to the encoding method. Therefore, each time that you use PROC PWENCODE to encode the same password, you get a different encoded password, because the salt values are random. In addition to the random salt value, SAS005 is hashed for additional iterations. SAS005 is the highest level of encoding that is used with PROC PWENCODE.

SASProprietary for SAS data set encryption with passwords is a cipher that uses parts of the passwords that are stored in the SAS data set as part of the 32-bit rolling key encoding of the data. This encryption provides a medium level of security. With the speed of today's computers, it could be subjected to a brute force attack on the 2,563,160,682,591 possible combinations of valid password values, many of which must produce the same 32-bit key.

SASProprietary data set password encryption is primarily used with customer data from legacy SAS systems. For example, SASProprietary might be used with SAS 9 data in the SAS Metadata Server, the workspace server in SAS Viya 3.5 and earlier releases, or the SAS Compute Server in the SAS Viya platform.

Last updated: September 15, 2026