What it does
bcrypt is a password hashing function designed to be slow. Unlike MD5 or SHA-256, which can be computed billions of times per second, bcrypt has a configurable cost that makes each guess expensive for an attacker who steals your database. It is still one of the most widely used choices for storing passwords, next to Argon2 and scrypt.
This tool does two things:
- Hash: turn a password into a bcrypt hash with the cost and version prefix you choose.
- Verify: check whether a password matches an existing bcrypt hash, for example one from your database or a framework’s seed file.
How to use
- Type a Password, or click Sample.
- In Hash mode, choose the Cost and Version. The hash appears immediately; click New salt to get another one.
- In Verify mode, paste the bcrypt hash to check. The result says whether the password matches.
Reading a bcrypt hash
A hash such as $2b$10$./3kakECWB0QfIgYzIqciuv449HNnwGbgExtJQQwQ1MofonthOdoK has four parts: the version 2b, the cost 10 (2¹⁰ rounds of key setup), a 22-character salt, and a 31-character checksum. Everything a server needs to verify a password later is inside this one string, so you store only the hash.
Limits to know
bcrypt reads only the first 72 bytes of a password. Longer passwords, or passwords with many non-ASCII characters (each can take 2–4 bytes in UTF-8), are silently cut. The tool warns you when that happens. If you need to accept very long passphrases, pre-hash them or consider Argon2id.
FAQ
› Why do I get a different hash every time for the same password?
Each hash uses a new random 16-byte salt, which is stored inside the hash itself. That is intentional, so equal passwords do not produce equal hashes. To check a password, use Verify instead of comparing hash strings.
› Which cost should I use?
Pick the highest cost your server can afford for each login, usually 10 to 12 today. Every step doubles the work. Measure on your production hardware; around 100–300 ms per hash is a common target.
› What is the difference between $2a$, $2b$ and $2y$?
They are the same algorithm. $2b$ is the current prefix from OpenBSD, $2y$ is what PHP's password_hash writes, and $2a$ is the older one. Most libraries accept all three, so pick the one your system expects.
› Is my password sent anywhere?
No. Hashing and checking run in your browser. The password and the hash you check are kept only in memory on this page; they are not saved and not added to share links.