Local password hashing

Bcrypt Generator

Generate a salted bcrypt password hash or check whether a password matches an existing hash. Hashing and verification run locally in this browser tab.

Generate a bcrypt password hash

Use this for development, migration, and test fixtures. Do not enter a password that you currently use for a real account.

Bcrypt processes at most 72 UTF-8 bytes. 0 / 72 bytes
Benchmark verification in the destination application before increasing cost.
The generated password is separate from the salt embedded in the hash.

Bcrypt with random saltCost 1024 password bytes
Processed in this tabThe page code does not submit the password or hash to a hashing service. Browser extensions may still have access to page content, so prefer your application's native command for production credentials.

Verify a password against a bcrypt hash

Verification recomputes the hash using the embedded salt and cost, then compares the result. It does not reveal the original password.

Bcrypt hash checker

Not checked

Which bcrypt cost should you use?

A bcrypt cost is a base-two work factor. Cost 10 performs roughly 1,024 key-expansion rounds; each increase approximately doubles the work. OWASP treats bcrypt as a legacy-compatible choice when Argon2id or scrypt is unavailable and recommends a work factor of at least 10. Benchmark the real server and tune the cost so authentication remains usable while guesses stay expensive.

The 72-byte password limit

Most bcrypt implementations use only the first 72 bytes, not necessarily 72 visible characters. Unicode characters may occupy multiple UTF-8 bytes. This tool rejects longer input instead of silently truncating it. Confirm the exact behavior of the library used by the destination application.

Bcrypt versus SHA-256, SHA-1, and MD5

Fast digest functions are useful for integrity checks, but they are deliberately fast and are not suitable for storing login passwords by themselves. Do not choose MD5, SHA-1, or a single SHA-256 digest merely because another tool can produce one. Password storage needs a slow, salted password-hashing function and a migration plan as recommendations change.

Compatibility and prefixes

This page generates the modern $2b$ prefix from the local bcrypt library and verifies complete $2a$, $2b$, and $2y$ hashes. A destination framework may emit or prefer a different compatible prefix. Use its built-in password API whenever possible so format upgrades and rehash checks stay under application control.

Use a framework API in production

For application accounts, generate hashes in the same runtime that will verify them. PHP provides password_hash() and password_verify(); other platforms provide equivalent password-hashing APIs. Keep plaintext passwords out of command history, logs, URLs, analytics, and support messages.

References

Review the OWASP Password Storage Cheat Sheet, PHP's official password_hash() documentation, and the local library's bcrypt.js project.

Related tools

.htpasswd generator creates an Apache- and nginx-compatible username:hash line. Password strength checker evaluates a candidate locally without hashing it. Random key generator creates high-entropy key material rather than a password verifier. Hash generator calculates fast file and text checksums; those hashes are not password-storage substitutes.