Bcrypt
Hash and verify passwords with bcrypt
Enter a password first to generate a bcrypt hash or verify a match immediately; cost tuning and scenarios are available in Advanced mode.
The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.
About this tool
Generate real bcrypt hashes locally with bcryptjs, or compare a password with a $2a$, $2b$ or $2y$ hash. This browser tool accepts costs 4–14 and passwords up to 72 UTF-8 bytes; it rejects longer inputs rather than silently truncating them. Passwords and hashes are not saved as drafts.
Production Snippets
Verify an independent Apache bcrypt fixture
text
Password: MySecret123!
Hash: $2y$04$BLjjKhVx2E5i/Ij8NnZa6ex2sz./wIRexhrAm1SWOAuaiHpuk8SKq
Verify: match
Password: WrongSecret123!
Verify: mismatch
Cost 4 is only a fast test fixture.Frequently Asked Questions
Is bcrypt encryption?
No. bcrypt is a salted, deliberately expensive password hash. Verification recomputes the hash with the stored salt; there is no decrypt operation. A weak password can still be guessed.
Which hashes can this tool verify?
It accepts complete 60-character $2a$, $2b$ and $2y$ bcrypt hashes with costs 4–14. A valid but different password returns a mismatch; malformed or higher-cost hashes return an input error. This browser cap is not a limit of the bcrypt format.
Why can the same password produce different hashes?
Each generation chooses a fresh random salt. Compare a password against its hash with Verify; comparing two newly generated hash strings for equality is not a password check.
Does 72 bytes mean 72 characters?
No. The limit applies to UTF-8 bytes. ASCII usually takes one byte, many Chinese characters take three, and many emoji take four. This tool rejects inputs above 72 bytes in both modes.
How should I choose a production cost?
Each increment roughly doubles the work. Benchmark the authentication service on its real hardware and follow its password policy; this browser timer does not establish a safe universal cost. Use synthetic passwords for debugging.
What about hashes made by the earlier version of this page?
The earlier implementation used PBKDF2 under a bcrypt-looking prefix and was not standard bcrypt. Do not treat those strings as compatible hashes. Recreate test fixtures with this version; account migrations need the authentication system’s normal password reset or migration process.
Keep browsing