Bcrypt Hash Generator
Generate and verify bcrypt password hashes in your browser. Choose the cost factor, pick $2y$, $2b$ or $2a$, and nothing you type is transmitted.
Hash a password
Nothing you type here is sent anywhere — the hashing runs in this tab.
The digest is identical whichever you pick — the prefix is only the label the reading system expects.
Check a password against a hash
Paste a hash beginning $2a$, $2b$ or $2y$.
Related tools
All Security tools →This tool runs entirely in your browser. Nothing you enter is sent to our servers, so there is nothing for us to store or see.
About the Bcrypt Hash Generator
Bcrypt is a password hashing function designed to be slow. That sounds like a flaw and is the entire point: a fast hash such as SHA-256 lets an attacker who steals your database try billions of guesses a second, while bcrypt lets you dial the cost up until each guess is expensive enough that a stolen table is worth very little. The cost factor here is that dial — every step doubles the work, for you at login and for anyone attacking the result.
Use this to produce a hash for a seed file, a configuration entry or a test fixture, and to check an existing hash against a password when you are debugging a login that will not work. The output is the standard 60-character crypt form that PHP, Node, Python, Ruby, Go and Apache htpasswd all read — verified against PHP's own password_verify(), not merely self-consistent.
Everything runs in your browser. Bcrypt is implemented here in JavaScript rather than called on our server, because a tool that asks for a password and then sends it somewhere has defeated itself, and because an endpoint that runs a deliberately expensive hash on request is a way to exhaust a server with a single request. The work happens in a background thread on your own machine, so a high cost factor makes the page slow rather than unresponsive.
One thing worth knowing before you rely on the result: bcrypt reads only the first 72 bytes of a password and silently ignores the rest. The tool warns you when you cross that line.
How to use the Bcrypt Hash Generator
-
Type the password
Enter it in the first field. It stays in this tab — there is no network request involved in hashing, which you can confirm by disconnecting after the page loads and hashing anyway.
-
Choose a cost factor
Twelve is a sensible default in 2026. The advice under the slider tells you what each setting means, and the timing shown after hashing is measured on your own device.
-
Pick the prefix your system expects
Use $2y$ for PHP, $2b$ for most modern libraries and $2a$ only for something old. The digest is identical in all three — only the label differs.
-
Generate and copy the hash
Press Generate and copy the 60-character result straight into your database, seed file or htpasswd. A fresh salt is used every time, so hashing the same password twice gives two different hashes.
-
Check a hash when a login misbehaves
Paste an existing hash and the password it should match into the lower panel. This is the only way to test a bcrypt hash — there is nothing to decode.
Frequently asked questions
Can a bcrypt hash be decrypted back to the password?
No. Bcrypt is a one-way function, not encryption — there is no key that reverses it and no bcrypt decrypter exists. The only way to test a hash is to hash a candidate password with the same salt and cost and compare, which is exactly what the checker on this page does.
Why does the same password give a different hash every time?
Because each hash uses a new random 16-byte salt, which is stored inside the hash itself. That is what stops an attacker precomputing a table of common passwords, and it is why you verify a password by re-hashing rather than by comparing two hashes directly.
What cost factor should I use?
The usual advice is to pick the highest cost your production hardware can absorb in about a quarter of a second per login. That is around 12 on typical server hardware in 2026. Ten is still common but has not kept pace with hardware, and anything at or below eight is too cheap to be worth much.
What is the difference between $2a$, $2b$ and $2y$?
They mark which historical implementation produced the hash. The variants exist because of two bugs in old C code — a sign-extension problem and a length overflow — that a correct implementation cannot reproduce, so all three produce the same digest here. Pick whichever your library expects to read: PHP writes $2y$, most modern libraries write $2b$.
Is my password sent to your server?
No. Bcrypt is implemented in JavaScript on this page and runs in a background thread in your own browser, so the password never leaves your device. There is no upload endpoint for this tool to call even if something tried to.
Why does bcrypt ignore anything past 72 characters?
The key schedule reads exactly 72 bytes, so longer passwords are truncated — and two long passwords sharing their first 72 bytes produce identical hashes. Note that is bytes, not characters: accented or non-Latin text uses two to four bytes each, so a passphrase can cross the limit sooner than it looks. This page warns you when yours does.
Should I use bcrypt for new projects?
It is a perfectly reasonable choice and is supported everywhere. Argon2id is the current recommendation where it is available, because it is memory-hard and therefore harder to attack with custom hardware. Bcrypt remains far better than any general-purpose hash such as MD5, SHA-1 or SHA-256, which should never be used for passwords.