Skip to content
Accessibility
Theme
Text size
High contrast
Limit animations
Readable fontAtkinson Hyperlegible
Increased text spacing
Underline links
Always show focus

Runs in your browser — nothing you paste is uploaded.

Bcrypt Hash Generator & Verifier

Hash a password with bcrypt, or check a password against an existing hash. Pick the cost factor to trade speed for brute-force resistance. Everything runs in your browser — the password is never uploaded.

Higher cost = slower hash = harder to crack. 10–12 is typical.


      

What bcrypt is for

Bcrypt is a password-hashing function designed to be deliberately slow, which makes large-scale guessing attacks expensive. It stores a random salt inside the hash and applies a configurable number of rounds, so the same password hashes differently every time and a leaked hash is costly to reverse. Use it to store login passwords — not for general-purpose checksums, where a fast hash like SHA-256 is appropriate.

The cost factor

The cost is a base-2 exponent: cost 10 runs 210 = 1024 key-expansion rounds, cost 12 runs four times as many. Pick the highest value your server can tolerate on each login without an annoying delay — commonly 10 to 12. Raising it later is painless because the cost is recorded in every hash, so old and new hashes verify side by side.

Hashing and verifying

Hash

Type a password and click Hash password to get a $2a$<cost>$<salt+digest> string. Because of the random salt, each click produces a different hash — that is expected and correct.

Verify

Switch to Verify, paste an existing hash and the password, and the tool reports whether they match. It reads the cost and salt from the hash itself, so it works with $2a$, $2b$ and $2y$ hashes produced elsewhere (PHP password_hash(), Node, Python, etc.).

Privacy

Hashing and verification run entirely in your browser with a self-hosted bcrypt library; the password and hash are never sent anywhere. Related: htpasswd lines for Apache/nginx, the WordPress password hash tool, and a strong password generator.

WordPress $wp$ hashes

A WordPress 6.8+ hash looks like $wp$2y$… and will not verify here: WordPress pre-hashes the password with HMAC-SHA384 before bcrypt, so it isn't plain bcrypt. Use the WordPress Password Hash tool, which handles the full $wp$ scheme.

Related tools