HASH?

Password Hash Identifier

Inspect candidate hash formats and embedded parameters

Password Security
🔒 100% client-side — your data never leaves this page
Maintained by Evan•Updated: September 30, 2026
Password hash format

This tool identifies candidate formats from string structure only. It does not verify, crack, or audit the original password.

Identification result

Candidate algorithms, confidence, and parsed parameters will appear here.

About this tool

Paste one stored value to inspect format candidates based on prefixes, separators, alphabets, lengths and work parameters. Complete bcrypt and selected crypt or LDAP digest shapes receive stronger structural confidence; PHC-style, application-specific and wrapper matches remain candidates because this tool does not validate all inner parameters. Raw hexadecimal values receive low-confidence bit-length classifications. The legacy PostgreSQL verifier has the form md5 plus MD5(password + username), without the per-session challenge salt. No candidate proves the value’s origin, correctness, password strength or security. Matching is local, with no password cracking or verification.

Scenario Recipes

01

Triage hashes during a password-store migration

Goal: Group legacy records before choosing a verification and rehash strategy

  1. Paste one representative stored value and record the top candidate and confidence.
  2. Repeat for each distinct prefix or shape, keeping low-confidence raw digests separate.
  3. Confirm formats in the source application's code or documentation before implementing verification and login-time rehashing.

Result: A preliminary format inventory that preserves uncertainty instead of treating guesses as proof.

Frequently Asked Questions

Does High confidence mean a verified hash?

No. It means that more structural checks agree, such as prefix and expected length. No password is verified, and matching strings can be fabricated.

Why are some prefixed formats Medium confidence?

A recognizable wrapper or parameter layout may still contain unsupported or invalid inner data. The result preserves that uncertainty instead of certifying the full representation.

Why is a 32-character hexadecimal value Low confidence?

It could be MD5, NTLM, another 128-bit digest or an unrelated identifier. Length alone does not establish the algorithm.

Which parameters can I inspect?

Depending on the format: bcrypt cost, Argon2 version/memory/time/parallelism, scrypt work factors, PBKDF2 iterations and crypt rounds. Their presence is not an assessment of safe settings.

What should follow identification?

Confirm the format in the originating application’s documentation or code, then use its compatible verifier. This tool neither cracks hashes nor replaces migration or security review.

Keep browsing