Bcrypt Hash Generator & Verifier

Hash a password with bcrypt at a chosen cost, see how long it takes, and check whether a password matches an existing bcrypt hash.

Loading tool…

About the Bcrypt Generator

bcrypt is a password hashing function designed to be slow. Its cost factor is a power of two: cost 10 means 210 = 1,024 rounds of the expensive Blowfish key setup, and each +1 doubles the time. The timing shown helps you pick a cost; OWASP recommends at least 10, and a common target is 100–300 ms per hash on your production server (a browser is usually a little slower).

A bcrypt hash is 60 characters: $2a$10$ (version and cost), 22 characters of salt and 31 characters of hash, all in bcrypt's own Base64 alphabet. Because a new random 16-byte salt is generated each time, hashing the same password twice gives different results — that is expected. To check a password, the verifier re-hashes it with the salt and cost stored in the hash; the $2a$, $2b$ and $2y$ prefixes are all accepted.

bcrypt only uses the first 72 bytes of the password; the tool warns when your input is longer. Hashing runs locally with the bcrypt.js library, off the input event with a short delay so typing stays responsive. For real users' passwords, hash on your server, not in a web page.

How to use it

  1. Enter the password to hash.
  2. Set the cost factor (10 is a good default) and wait for the hash.
  3. Copy the hash, or click “New salt” for another one.
  4. To verify, enter a password and a bcrypt hash in the right panel.

Frequently asked questions

Why do I get a different hash every time?
Each hash includes a new random salt. Verification works because the salt is stored inside the hash string.
What cost factor should I use?
The highest your servers can afford at peak login load, typically 10–12 today. Re-hash on login when you raise it.
What is the difference between $2a$, $2b$ and $2y$?
They mark fixes to bugs in older implementations. $2b$ is current; $2y$ is PHP's equivalent. Modern libraries verify all three.
Should I use bcrypt or Argon2?
Argon2id is the current recommendation for new systems because it is also memory-hard. bcrypt remains a solid, widely supported choice.

Related tools