Bcrypt Hash Generator & Checker Online — Free
Runs 100% in your browser — your files never leave your device.
Bcrypt is the workhorse password-hashing algorithm behind countless login systems. Hash a password with the cost factor you choose, or paste an existing $2b$ hash to check whether a password matches it. Cost factors run from 4 to 12 here so the computation stays snappy in your browser tab.
How it works
- 1
Enter a password
Type the password you want to hash or verify.
- 2
Hash or compare
Generate a new hash at your chosen cost, or paste a hash to check a match.
- 3
Copy the result
The salted bcrypt hash is ready to paste into your config or database.
About this tool
Why bcrypt exists
Ordinary hashes are too fast — attackers try billions per second on modern hardware. Bcrypt is deliberately slow and carries a salt automatically, so identical passwords hash differently and each guess costs real time. It is the correct way to store password hashes.
The cost factor
The cost (4–12 here) is an exponent: each step doubles the work. Higher costs mean slower verification for you and slower guessing for attackers — pick the highest value your login flow can tolerate, and re-hash with a higher cost as hardware improves.
Verify as well as generate
Paste an existing hash and a candidate password to check whether they match — verification is how login flows work, and the tool runs the same comparison locally. Your passwords never leave the device.
Frequently asked questions
Is bcrypt output the same for the same password?
No — bcrypt generates a fresh salt for every hash, so the same password produces a different hash each time. Verification re-runs the hash with the stored salt instead of comparing directly.
What cost factor should I use?
The rule of thumb: the highest cost that keeps your login under about 250 milliseconds. On typical hardware that is 10–12, and it climbs as processors get faster.
Can I recover a password from a bcrypt hash?
No — bcrypt is one-way. Verification works by hashing the candidate and comparing, which is why password resets replace the hash rather than emailing the old password.