Security / Passwords

bcrypt Hash Generator and Checker

Generate a bcrypt password hash with the cost you choose, or check whether a password matches an existing hash, entirely in your browser.

bcrypt Hash Generator and Checker: bcrypt, designed by Niels Provos and David Mazières in 1999, runs the Blowfish key schedule 2^cost times with a random 16-byte salt, so each guess costs an attacker the same slow work. The result holds the version, cost, salt, and hash in one 60-character string. The implementation here was checked against the Python bcrypt package, including Unicode and over-long passwords. Runs 100% locally in your browser with zero server file uploads.

Runs
In your browser
Cost
Free · no sign-up
Availability
Ready to use
bcrypt generatorLocal processing

Runs entirely in your browser

Everything runs in this browser; the password and hash are never sent anywhere. Cost 10–12 suits most logins: each step up doubles the time.

Storing passwords safely

Never store passwords as plain text or with a fast hash such as MD5 or SHA-256, which a graphics card can try billions of times a second. bcrypt, scrypt, and Argon2 are deliberately slow and salted, so a stolen database is far harder to crack.

For web server logins, the htpasswd generator writes complete user lines; to create the passwords themselves, use the password generator.

Reading a bcrypt hash

In $2b$12$R9h/cIPz0gi.URNNX3kh2OPST9/PgBkqquzi.Ss7KIUgO2t0jWMUW, 2b is the version, 12 the cost, the next 22 characters the salt, and the last 31 the hash. Because the salt and cost travel with the hash, a server can raise the cost for new passwords without breaking old ones.

How to use it

  1. Type the password and choose a cost; 10 to 12 suits most sites.
  2. Generate the hash and copy it into your database or configuration.
  3. To test a stored hash, switch to checking, paste the hash, and type the password.

Privacy & limitations

The password and hash stay in your browser; nothing is sent to a server.

Related tools

Frequently asked questions

Which cost should I use?

The highest your server can afford per login, typically 10–12; OWASP recommends at least 10. Each step doubles the time, so check the time shown here against your slowest server.

What is the difference between $2a$, $2b$, and $2y$?

They hash normal passwords identically. $2b$ marks OpenBSD's 2014 fix for very long passwords, and $2y$ marks PHP's 2011 fix of a bug in another implementation; PHP and Apache's htpasswd write $2y$, most other libraries $2b$.

Why is my long password accepted with only the start?

bcrypt only uses the first 72 bytes, and many libraries cut longer passwords silently; the tool warns when that happens. Letters outside English take 2–4 bytes each.

Free tool · runs in your browser · no account required