Security / Passwords
bcrypt Hash Generator and Checker
Generate a bcrypt password hash with the cost you choose, or check whether a password matches an existing hash, entirely in your browser.
bcrypt Hash Generator and Checker: bcrypt, designed by Niels Provos and David Mazières in 1999, runs the Blowfish key schedule 2^cost times with a random 16-byte salt, so each guess costs an attacker the same slow work. The result holds the version, cost, salt, and hash in one 60-character string. The implementation here was checked against the Python bcrypt package, including Unicode and over-long passwords. Runs 100% locally in your browser with zero server file uploads.
- Category
- Developer tools
- Runs
- In your browser
- Cost
- Free · no sign-up
- Availability
- Ready to use
Runs entirely in your browser
Everything runs in this browser; the password and hash are never sent anywhere. Cost 10–12 suits most logins: each step up doubles the time.
Storing passwords safely
Never store passwords as plain text or with a fast hash such as MD5 or SHA-256, which a graphics card can try billions of times a second. bcrypt, scrypt, and Argon2 are deliberately slow and salted, so a stolen database is far harder to crack.
For web server logins, the htpasswd generator writes complete user lines; to create the passwords themselves, use the password generator.
Reading a bcrypt hash
In $2b$12$R9h/cIPz0gi.URNNX3kh2OPST9/PgBkqquzi.Ss7KIUgO2t0jWMUW, 2b is the version, 12 the cost, the next 22 characters the salt, and the last 31 the hash. Because the salt and cost travel with the hash, a server can raise the cost for new passwords without breaking old ones.
How to use it
- Type the password and choose a cost; 10 to 12 suits most sites.
- Generate the hash and copy it into your database or configuration.
- To test a stored hash, switch to checking, paste the hash, and type the password.
Privacy & limitations
The password and hash stay in your browser; nothing is sent to a server.
Related tools
Frequently asked questions
Which cost should I use?
The highest your server can afford per login, typically 10–12; OWASP recommends at least 10. Each step doubles the time, so check the time shown here against your slowest server.
What is the difference between $2a$, $2b$, and $2y$?
They hash normal passwords identically. $2b$ marks OpenBSD's 2014 fix for very long passwords, and $2y$ marks PHP's 2011 fix of a bug in another implementation; PHP and Apache's htpasswd write $2y$, most other libraries $2b$.
Why is my long password accepted with only the start?
bcrypt only uses the first 72 bytes, and many libraries cut longer passwords silently; the tool warns when that happens. Letters outside English take 2–4 bytes each.
Free tool · runs in your browser · no account required