Bc

Bcrypt

Hash and verify passwords with bcrypt

Password Security
🔒 100% client-side — your data never leaves this page
Maintained by Evan•Updated: September 29, 2026
Options
Input

Enter a password first to generate a bcrypt hash or verify a match immediately; cost tuning and scenarios are available in Advanced mode.

10
Each increment roughly doubles the work. Browser timing is not a server benchmark; low costs are for tests.
🔒 Local bcryptjs computation · No password drafts
Output
Hash will appear here
Page reading mode

The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.

About this tool

Generate real bcrypt hashes locally with bcryptjs, or compare a password with a $2a$, $2b$ or $2y$ hash. This browser tool accepts costs 4–14 and passwords up to 72 UTF-8 bytes; it rejects longer inputs rather than silently truncating them. Passwords and hashes are not saved as drafts.

Production Snippets

Verify an independent Apache bcrypt fixture

text

Password: MySecret123!
Hash: $2y$04$BLjjKhVx2E5i/Ij8NnZa6ex2sz./wIRexhrAm1SWOAuaiHpuk8SKq
Verify: match
Password: WrongSecret123!
Verify: mismatch
Cost 4 is only a fast test fixture.

Frequently Asked Questions

Is bcrypt encryption?

No. bcrypt is a salted, deliberately expensive password hash. Verification recomputes the hash with the stored salt; there is no decrypt operation. A weak password can still be guessed.

Which hashes can this tool verify?

It accepts complete 60-character $2a$, $2b$ and $2y$ bcrypt hashes with costs 4–14. A valid but different password returns a mismatch; malformed or higher-cost hashes return an input error. This browser cap is not a limit of the bcrypt format.

Why can the same password produce different hashes?

Each generation chooses a fresh random salt. Compare a password against its hash with Verify; comparing two newly generated hash strings for equality is not a password check.

Does 72 bytes mean 72 characters?

No. The limit applies to UTF-8 bytes. ASCII usually takes one byte, many Chinese characters take three, and many emoji take four. This tool rejects inputs above 72 bytes in both modes.

How should I choose a production cost?

Each increment roughly doubles the work. Benchmark the authentication service on its real hardware and follow its password policy; this browser timer does not establish a safe universal cost. Use synthetic passwords for debugging.

What about hashes made by the earlier version of this page?

The earlier implementation used PBKDF2 under a bcrypt-looking prefix and was not standard bcrypt. Do not treat those strings as compatible hashes. Recreate test fixtures with this version; account migrations need the authentication system’s normal password reset or migration process.

Keep browsing