What bcrypt is for
Bcrypt is a password-hashing function designed to be deliberately slow, which makes large-scale guessing attacks expensive. It stores a random salt inside the hash and applies a configurable number of rounds, so the same password hashes differently every time and a leaked hash is costly to reverse. Use it to store login passwords — not for general-purpose checksums, where a fast hash like SHA-256 is appropriate.
The cost factor
The cost is a base-2 exponent: cost 10 runs 210 = 1024 key-expansion rounds, cost 12 runs four times as many. Pick the highest value your server can tolerate on each login without an annoying delay — commonly 10 to 12. Raising it later is painless because the cost is recorded in every hash, so old and new hashes verify side by side.
Hashing and verifying
Hash
Type a password and click Hash password to get a $2a$<cost>$<salt+digest> string. Because of the random salt, each click produces a different hash — that is expected and correct.
Verify
Switch to Verify, paste an existing hash and the password, and the tool reports whether they match. It reads the cost and salt from the hash itself, so it works with $2a$, $2b$ and $2y$ hashes produced elsewhere (PHP password_hash(), Node, Python, etc.).
Privacy
Hashing and verification run entirely in your browser with a self-hosted bcrypt library; the password and hash are never sent anywhere. Related: htpasswd lines for Apache/nginx, the WordPress password hash tool, and a strong password generator.
WordPress $wp$ hashes
A WordPress 6.8+ hash looks like $wp$2y$… and will not verify here: WordPress pre-hashes the password with HMAC-SHA384 before bcrypt, so it isn't plain bcrypt. Use the WordPress Password Hash tool, which handles the full $wp$ scheme.