About the Bcrypt Generator
bcrypt is a password hashing function designed to be slow. Its cost factor is a power of two: cost 10 means 210 = 1,024 rounds of the expensive Blowfish key setup, and each +1 doubles the time. The timing shown helps you pick a cost; OWASP recommends at least 10, and a common target is 100–300 ms per hash on your production server (a browser is usually a little slower).
A bcrypt hash is 60 characters: $2a$10$ (version and cost), 22 characters of salt and 31 characters of hash, all in bcrypt's own Base64 alphabet. Because a new random 16-byte salt is generated each time, hashing the same password twice gives different results — that is expected. To check a password, the verifier re-hashes it with the salt and cost stored in the hash; the $2a$, $2b$ and $2y$ prefixes are all accepted.
bcrypt only uses the first 72 bytes of the password; the tool warns when your input is longer. Hashing runs locally with the bcrypt.js library, off the input event with a short delay so typing stays responsive. For real users' passwords, hash on your server, not in a web page.
How to use it
- Enter the password to hash.
- Set the cost factor (10 is a good default) and wait for the hash.
- Copy the hash, or click “New salt” for another one.
- To verify, enter a password and a bcrypt hash in the right panel.