[...] The first thing that concerns me -- something strong, like bcrypt, will make the REST interface, with its per-command authentication (lack of sessions) unworkably expensive [...]
I agree, performance is very essential here. What about using SHA-2? Christian