Store a password verifier
Generate or compare a bcrypt hash. Login systems compare a candidate password with the stored hash; they do not decrypt it.
Debug APIs, clean content, format data, and run release checks directly in your browser.
Focused on Password Security with 6 tools. Use search to narrow down quickly.
Filter by Focus
A password hash, reversible encryption and a time-based code solve different problems. Start with the operation your application needs; a successful conversion alone does not establish secure account handling.
Generate or compare a bcrypt hash. Login systems compare a candidate password with the stored hash; they do not decrypt it.
Use reversible encryption when the recipient must recover the original text. Key storage and the encryption format still need an application-level design.
Compare the same Base32 secret, SHA1 algorithm, number of digits, period and clock. A matching local code does not enroll an account.
RFC 6238 test secret (ASCII): 12345678901234567890 SHA1 · 8 digits · 30-second step Unix time 59 → 94287082
This is a fixed-time reference vector. The generator uses your current device time, so its live code will normally differ. When two live authenticators disagree, compare secret bytes and settings before blaming the password hash.
Use disposable examples. Password strength estimates and hash identification do not verify that an account exists, that a password has never leaked, or that a server correctly limits login attempts.
Hash and verify passwords with bcrypt
Password Security
Inspect a local score and common password patterns
Password Security
Encrypt and decrypt text with AES-GCM
Password Security
Generate SHA1 TOTP codes and compare local time windows
Password Security
Build a SHA1 otpauth URI, QR image, and current test code
Password Security
Inspect candidate hash formats and embedded parameters
Password Security