Verify a password against a bcrypt hash
Verification recomputes the hash using the embedded salt and cost, then compares the result. It does not reveal the original password.
Which bcrypt cost should you use?
A bcrypt cost is a base-two work factor. Cost 10 performs roughly 1,024 key-expansion rounds; each increase approximately doubles the work. OWASP treats bcrypt as a legacy-compatible choice when Argon2id or scrypt is unavailable and recommends a work factor of at least 10. Benchmark the real server and tune the cost so authentication remains usable while guesses stay expensive.
The 72-byte password limit
Most bcrypt implementations use only the first 72 bytes, not necessarily 72 visible characters. Unicode characters may occupy multiple UTF-8 bytes. This tool rejects longer input instead of silently truncating it. Confirm the exact behavior of the library used by the destination application.
Bcrypt versus SHA-256, SHA-1, and MD5
Fast digest functions are useful for integrity checks, but they are deliberately fast and are not suitable for storing login passwords by themselves. Do not choose MD5, SHA-1, or a single SHA-256 digest merely because another tool can produce one. Password storage needs a slow, salted password-hashing function and a migration plan as recommendations change.
Compatibility and prefixes
This page generates the modern $2b$ prefix from the local bcrypt library and verifies complete $2a$, $2b$, and $2y$ hashes. A destination framework may emit or prefer a different compatible prefix. Use its built-in password API whenever possible so format upgrades and rehash checks stay under application control.
Use a framework API in production
For application accounts, generate hashes in the same runtime that will verify them. PHP provides password_hash() and password_verify(); other platforms provide equivalent password-hashing APIs. Keep plaintext passwords out of command history, logs, URLs, analytics, and support messages.
References
Review the OWASP Password Storage Cheat Sheet, PHP's official password_hash() documentation, and the local library's bcrypt.js project.
Related tools
.htpasswd generator creates an Apache- and nginx-compatible username:hash line. Password strength checker evaluates a candidate locally without hashing it. Random key generator creates high-entropy key material rather than a password verifier. Hash generator calculates fast file and text checksums; those hashes are not password-storage substitutes.