Bcrypt Generator - Hash & Verify Passwords with bcrypt Online
Bcrypt Generator
Hash a password with bcrypt, or check whether a password matches a hash
Adjustable Cost
Every extra cost point doubles the work. Pick the cost that suits your servers, then see how long it took.
Verify Hashes
Paste an existing hash and a password to see if they match, and read the version and cost from the hash.
$2a$, $2b$ and $2y$
Choose the prefix your framework expects. They all verify each other for ordinary passwords.
Full Privacy
Hashing happens in your browser. Passwords never leave your device. Still, use test passwords here, not real ones.
Why bcrypt for Passwords
bcrypt is a deliberately slow, salted password hash. Each hash includes its own random salt, so equal passwords give different hashes, and a cost factor sets how many rounds (2 to the power of the cost) are done, so you can make guessing slower as computers get faster. A stored hash looks like $2b$10$ followed by 22 characters of salt and 31 of hash.
A cost of 10 to 12 is common today, aiming for roughly a quarter of a second per hash on your server. bcrypt reads only the first 72 bytes of a password, so very long passphrases are cut off, and it cannot hash more than that safely. Newer designs such as Argon2 and scrypt use memory as well as time, but bcrypt remains widely supported and sound. In the browser, costs above 12 are slow, so this tool stops at 14.
Key Takeaways
- Salted: Each run makes a fresh random salt, so hashing the same password twice gives different results, and both verify.
- 72-byte limit: A warning appears when your password is longer than bcrypt reads.
- Related tools: See the Password Generator, the Hash Generator and the htpasswd Generator.