Bcrypt Hash Generator & Verifier

Runs in your browserSecurity#Bcrypt

Generate bcrypt hashes and check passwords against them, with cost timing and a breakdown of the hash.

Recommended: 10 to 12. each step doubles the time.

How to use, limits & privacy

About Bcrypt Hash Generator & Verifier

Create bcrypt password hashes and check a password against an existing hash, in your browser. Choose the cost and see how long it takes on your device, read a hash broken into version, cost, salt and hash, and cancel slow jobs. Useful for developers testing logins, seeding databases or debugging password checks.

How to Use

1

Pick a mode

Choose Generate hash to make a new hash, or Verify password to test a password against a hash you already have.

2

Enter the details

Type the password (the eye button shows it). To generate, set the Cost; 10 to 12 is recommended. To verify, paste the bcrypt hash; its parts are shown as soon as it is valid.

3

Run and copy

Click Generate hash or Verify, or press Enter. Copy the hash with the copy button. Slow jobs show progress and can be cancelled.

Privacy & Processing

  • Mode: local
  • Files Leave Browser: Local tool processing; review details below
  • Max Input Size: Device memory limits
  • Account Required: No
  • Data Stored Locally: Nothing is saved; inputs and results disappear when you leave the page.
  • Network Processing: Assets or models may require an initial download

Passwords and hashes stay in your browser; hashing runs in a local Web Worker and nothing is uploaded.

Rules & Limitations

  • Passwords can be up to 72 bytes (UTF-8). Bcrypt ignores anything longer, so longer passwords are refused.
  • Generates $2b$ hashes with cost 4 to 14; verifies $2a$, $2b$ and $2y$ hashes with cost 4 to 16. Each cost step doubles the time, and phones are often 3 to 5 times slower than laptops.
  • Hashing runs in a background worker, so the page stays responsive.
  • The same password gives a different hash every time because the salt is random. Use Verify to compare.

Top Suggestions

  • Creating a test user's password hash for a database seed
  • Checking whether a stored hash matches a password while debugging a login
  • Choosing a cost factor that is slow enough but fast enough for your server
  • Reading the cost and salt of an existing hash

Bcrypt Hash Generator & Verifier FAQ

How do I verify a bcrypt hash?

Choose Verify password, type the password, paste the hash (it starts with $2a$, $2b$ or $2y$ and is 60 characters long) and click Verify. You will see whether the password matches.

What cost factor should I use for bcrypt?

Use 10 to 12 for web logins. Pick the highest cost your server can handle at about a quarter of a second per login. The tool shows the time for each cost on this device, and each step up doubles it.

Why does the same password give a different bcrypt hash?

Each hash includes a new random 22-character salt, so two hashes of one password never match as text. Bcrypt checks a password by hashing it again with the salt stored in the hash.

What is the difference between $2a$, $2b$ and $2y$?

They are versions of the same algorithm. $2b$ is the current one; $2a$ is older and $2y$ comes from PHP. For normal passwords they give the same result, and this tool verifies all three.

Is it safe to enter real passwords here?

Hashing and checking happen in your browser and nothing is sent or saved. Still, avoid pasting production passwords and hashes into any web page if your security policy forbids it.