Bcrypt Hash Generator & Verifier
Hash a password with bcrypt or check whether a password matches an existing bcrypt hash. Choose the cost factor, see how long hashing takes, and understand each part of the hash — all computed locally in your browser.
Enter a password and choose a cost factor (10–12 is typical) to generate a salted bcrypt hash like $2b$10$…. To verify, switch to Verify, paste the hash and the password, and the tool tells you whether they match. Bcrypt can't be decrypted — only checked.
OWASP recommends 10 or more. Each +1 doubles the time.
Zero Server Uploads
Files process in local RAM
Instant WASM Speed
No waiting queues or lags
Unlimited Batching
Convert files without limits
Suggest a Feature or Improvement for Bcrypt Generator
Need custom options, higher limits, or extra format support? Let our engineering team know!
How to use Bcrypt Generator
- 1Choose Generate or Verify.
- 2Enter the password (bcrypt uses the first 72 bytes).
- 3Set the cost factor, or paste the hash to verify.
- 4Copy the hash or read the match result.
Why bcrypt for passwords
Bcrypt is deliberately slow and salted. Each hash includes a random 128-bit salt, so identical passwords get different hashes, and the cost factor makes every guess expensive: at cost 12, an attacker can test only thousands of guesses per second per GPU instead of billions for MD5 or SHA-256.
Raise the cost as hardware gets faster; the cost is stored in the hash, so old and new hashes can coexist.
Reading a bcrypt hash
$2b$10$N9qo8uLOickgx2ZMRZoMye… breaks down as: $2b$ the version, 10 the cost (2^10 rounds), the next 22 characters the salt, and the last 31 the hash. $2a$, $2b$ and $2y$ (PHP) are compatible for normal passwords. For new systems, Argon2id is the current OWASP first choice, with bcrypt still widely acceptable.
Frequently Asked Questions
Can a bcrypt hash be decrypted?
No. Bcrypt is a one-way function. The only way to “reverse” it is to guess passwords and check each one, which the cost factor makes slow.
What cost factor should I use?
OWASP recommends at least 10. Pick the highest value that keeps login under about 250 ms on your server.
Why does the same password give a different hash each time?
A new random salt is generated for every hash. Verification reads the salt from the stored hash, so it still works.
Is my data sent to your server?
No. This tool runs entirely in your browser using the Web Crypto API and JavaScript. Nothing you type or generate is uploaded, logged or stored.
Related Tools
Password Strength Checker
Test how strong your password really is, how long it takes to crack, and whether it's been breached.
SHA-256 Hash Generator
Generate SHA-256 hashes of text or files instantly — hex or Base64, with checksum comparison.
HMAC Generator
Generate and verify HMAC signatures with SHA-256, SHA-512, SHA-1, MD5 or SHA-3.