Bcrypt Generator & Verifier

Hash a password with bcrypt or check one against a hash.

Free. Runs in your browser: nothing you enter or open is uploaded.

Hashing runs in a background worker in your browser using bcryptjs (BSD licence), so nothing you type is sent anywhere and the page stays responsive at high cost factors. Hashes start with $2b$, the current version, and are accepted by PHP password_verify, Node bcrypt, Python bcrypt, Spring Security and most other libraries. For real accounts, your application should hash passwords on its own server; use this page for testing, migrations and checking a hash.

How to use it

  1. Type a password and pick a cost factor. 10 to 12 suits most web applications today.
  2. Press Hash it. The salt is random, so the same password gives a different hash every time.
  3. To check a password, open Check a password, paste the hash and the password, and press Check.

Questions

Why is the hash different every time?

bcrypt mixes a new random 16 byte salt into every hash and stores it inside the hash string. That stops attackers using precomputed tables, and the salt is read back when you verify, so every one of those hashes still matches the password.

Which cost factor should I use?

Pick the highest your server can afford: one hash should take roughly 100 to 300 milliseconds. Each step up doubles the work, so cost 12 takes four times as long as 10. The timer here shows how long it took on your device.

Is there a length limit?

Yes. bcrypt only uses the first 72 bytes of the password. Longer passwords are cut off, so two that share the same first 72 bytes match each other. The page warns you when that happens. Accented letters and emoji take more than one byte each.

What do $2a$, $2b$ and $2y$ mean?

They are versions. $2a$ is the original, $2y$ is PHP's fixed version and $2b$ is the current one. They produce the same result for normal passwords, and most libraries accept all three.