Bcrypt Hash Generator & Checker

Hash a password with bcrypt at a cost from 4 to 14, check a password against an existing hash, or paste a hash to see its version, cost, salt and digest.

Generator Web & Dev Updated Oct 4, 2026
Learn how this works
How to Use
  1. Choose Hash to make a new hash, Check to test a password against one, or Parse to take a hash apart.
  2. Type the password. It is hidden by default; tick Show to see it. The byte count warns when it goes past bcrypt’s 72-byte limit.
  3. For a new hash, set the cost (10 is a common default; every step doubles the time) and the version prefix, then press Hash.
  4. To check, paste the stored hash and press Check. The salt and cost are read from the hash itself.
  5. Copy the hash with Copy hash or by clicking it, and read Show Work for the parts and the measured time.
Input
0 bytes
4–14, rounds = 2cost
10 (1,024 rounds)
Passwords are hashed in this page with the bcryptjs library: nothing is uploaded, saved or put in the address bar.
Presets
Hash
—
The hash parts and the cost-versus-time chart appear here.
Cost
—
Time
—
Salt
—
Result
—

Worked Example

PHP’s password_hash('correct horse battery staple', PASSWORD_BCRYPT) returned this 60-character hash:

$2y$10$nV9npHEdpvSm4yeWWsHTYukOsExWGwSSyi9oMfQ3zAhc6sc6/9kwm

1. $2y$: the version, PHP’s label for bcrypt.
2. 10: the cost, so the key setup runs 210 = 1,024 times.
3. nV9npHEdpvSm4yeWWsHTYu: 22 characters of bcrypt’s own Base64 (alphabet ./A–Za–z0–9) holding the 16-byte salt a57fe9ac919faf1528eb481862e2556b.
4. kOsExWGwSSyi9oMfQ3zAhc6sc6/9kwm: 31 characters holding the 23-byte result 990b86cd…7f9b2a.
Checking “correct horse battery staple” against it matches; “Correct horse battery staple”, with one capital letter, does not.

The OpenBSD test vector shows the format is fixed: the password “U*U” with cost 5 and the salt CCCCCCCCCCCCCCCCCCCCC. always gives $2a$05$CCCCCCCCCCCCCCCCCCCCC.E5YPO9kmyuRGyh0XouQYb4YMJKvyOeW.

The common mistake: checking a login by hashing the typed password again and comparing the two strings. The new hash gets a new random salt, so it never equals the stored one and every login fails, even with the right password. Pass the stored hash to password_verify() or bcrypt.compare(), which reuse its salt and cost.

Show Work

Hash a password, check one against a hash, or paste a hash to see its parts.

Formulas

Hash layout
$2b$cc$ + 22 salt + 31 hash
4 + 2 + 1 + 22 + 31 = 60 characters
Work
rounds = 2cost
Cost 10 = 1,024; cost 12 = 4,096; cost 14 = 16,384
Time
t(c + 1) ≈ 2 × t(c)
Each cost step doubles the time, for you and an attacker
Salt
16 bytes = 128 bits → 22 chars
22 × 6 = 132 bits; the last character is one of . O e u
Hash
23 bytes = 184 bits → 31 chars
Encrypt “OrpheanBeholderScryDoubt” 64 times, drop the last byte
Password limit
used = min(bytes + 1, 72)
UTF-8 bytes plus a zero byte; the rest is ignored

A Password Hash Built to Be Slow

Niels Provos and David Mazières presented bcrypt at USENIX in 1999 in the paper “A Future-Adaptable Password Scheme”, and it was already OpenBSD’s password hash. It is built on Bruce Schneier’s Blowfish cipher, whose key setup is unusually slow; bcrypt’s “Eksblowfish” (expensive key schedule Blowfish) repeats that setup 2cost times. The adjustable cost was the point: as computers got faster, the same function could be made slower with one number, without changing the format.

Its quirks have mattered in practice. The 72-byte limit caused a real flaw in 2024, when Okta reported that a cache key built by bcrypt-hashing the user ID, username and password ignored the password once the username was long enough. The modern successor is Argon2, winner of the Password Hashing Competition in 2015 and standardised as RFC 9106 in 2021, which adds a memory cost that bcrypt lacks.

About This Tool

This tool makes bcrypt hashes at cost 4 to 14 with a $2b$, $2y$ or $2a$ prefix, checks a password against an existing hash, and takes any hash apart into version, cost, salt and digest, decoding both from bcrypt’s Base64. It times each run and charts what every other cost would take in the same browser.

Hashing uses the open-source bcryptjs library (MIT licence), served from this site and run in small slices so the page stays responsive. Everything happens in your browser: passwords and hashes are not uploaded, stored or added to the address bar. JavaScript bcrypt is slower than a server’s native code, so expect costs 13 and 14 to take a few seconds.

It suits developers setting up a login system, testing fixtures, migrating users between platforms, or choosing a cost.

Related tools: Password Generator, Hash Generator, and .htaccess Generator.

Frequently Asked Questions

Why does the same password give a different hash each time?

Every hash gets a fresh random 16-byte salt, stored in characters 8 to 29 of the result, so hashing “correct horse battery staple” twice gives two unrelated strings. That stops an attacker using one precomputed table for everyone and hides which users share a password. To check a password you do not hash it again and compare strings; you call password_verify() or bcrypt.compare(), which reuse the salt stored in the hash.

Which cost should I use?

The highest your login server can afford, usually 10 to 12. Each step doubles the work for you and for an attacker: cost 12 is 4,096 rounds, four times cost 10. The OWASP Password Storage Cheat Sheet asks for a work factor of at least 10, and PHP 8.4 raised its default from 10 to 12. Costs 13 and 14 take noticeably long here because this page runs bcrypt in JavaScript.

What is the 72-byte limit?

bcrypt only reads the first 72 bytes of the password. A password of 72 “a”s followed by anything at all matches the hash of the 72 “a”s alone, which one preset here shows. Accented letters, emoji and non-Latin scripts take 2 to 4 bytes each in UTF-8, so the limit can be as low as 18 characters. If longer passphrases must count, prefer Argon2id, or pre-hash the password (for example with SHA-256 and Base64) before bcrypt.

What do $2a$, $2b$ and $2y$ mean?

They name the same algorithm with different bug histories. $2a$ is the revision that defined UTF-8 and the terminating zero byte. $2y$ is PHP’s label since 2011, when a sign-extension bug in crypt_blowfish was fixed (old buggy hashes are $2x$). $2b$ is OpenBSD’s 2014 fix for a length counter that wrapped at 255 bytes. For ordinary passwords all three give identical hash bytes, and most libraries verify all three.

Is bcrypt still a good choice?

Yes, at cost 10 or more, but no longer the first choice. OWASP now recommends Argon2id, then scrypt, with bcrypt for systems that already use it. bcrypt needs only about 4 KB of memory, so graphics cards and FPGAs can attack it more cheaply than memory-hard Argon2id. It is far better than any fast hash: SHA-256 can be guessed billions of times per second on one GPU.

How do I use the Bcrypt Hash Generator & Checker?

Just pick your options. The answer shows up right away — there is no button to press. Change anything and it updates by itself.

Do I need to install or sign up for anything?

Not at all — it runs in the browser with nothing to install and no account. After it loads once, it even works without an internet connection.

Is my information private?

Yes. Everything happens in your browser. Nothing you type is sent to a server or saved anywhere.

Common Use Cases

Seeding an admin account

Make a $2y$ hash at cost 12 for a database seed or a config file, so the plain password never sits in the repository.

Apache .htpasswd

htpasswd -B stores bcrypt hashes with a default cost of 5. Check a line’s hash here, or make a stronger one at cost 10.

Moving between languages

A $2y$ hash from PHP’s password_hash() verifies in Node, Python and Go libraries. Paste it into Check to confirm before migrating users.

Debugging “wrong password”

If the stored hash is not 60 characters, the database column truncated it: VARCHAR(50) cuts off the last 10 characters of the hash.

Choosing a cost

Hash once and read the chart: if cost 10 takes 70 ms here, cost 12 takes about 280 ms and cost 14 over a second.

Last updated: