Bcrypt Generator & Checker
Hash a password with bcrypt, or check whether a password matches a hash from your database — with the version, cost and salt explained and the 72-byte limit flagged.
At a glance
- Creates bcrypt hashes with a cost from 4 to 16 and the $2b$, $2y$ (PHP, Laravel) or $2a$ prefix, using a fresh 16-byte random salt each time.
- Checks a password against a bcrypt hash as you type — $2a$, $2b$, $2y$, ASCII $2x$ and Django’s bcrypt_sha256 hashes are supported.
- Breaks a hash into version, cost, salt and checksum, and recognises Argon2, SHA-crypt, phpass and plain MD5/SHA hashes pasted by mistake.
- Warns when a password is over 72 bytes — bcrypt ignores the rest — and counts bytes, not characters, so Hindi and emoji are measured correctly.
- Measures how long a hash takes on your device and estimates other costs; hashing runs in a background thread so the page never freezes.
- Verified against the OpenBSD and jBCrypt test vectors. Passwords and hashes never leave your browser and are not saved.
Step by step
How to generate or check a bcrypt hash
- 1
Type the password
Enter it once at the top — both sides use it.
- 2
Generate
Pick a cost (12 is a good default) and a prefix, then press Generate hash and copy it.
- 3
Or check
Paste a hash under Check a password — the result appears as you type.
- 4
Read the details
See the version, cost and salt, and any warning about cost or length.
Features
Everything you need, nothing you don’t
Generate and check together
Type the password once, make a hash, and click “Check it” to confirm it verifies.
Hash explained
Colour-coded prefix, cost, salt and checksum, with the salt shown as bytes.
Typing slips
When a password doesn’t match, it checks for Caps Lock and stray spaces.
Real timings
See how long cost 10 to 14 takes on this device before choosing one for your server.
Cut-off hashes caught
A hash shorter than 60 characters usually means the database column is too small — it tells you so.
Private
Nothing is uploaded or stored; close the tab and it’s gone.
How bcrypt works
Bcrypt is a password-hashing function built to be slow on purpose. The cost is a power of two: cost 12 runs the expensive key setup 2¹² = 4,096 times, and each +1 doubles the time — for you and for anyone trying to guess passwords from a stolen database.
Every hash includes its own random salt, so the same password gives a different hash each time. That’s why you can’t “decrypt” bcrypt or compare two hashes directly — you check a password by hashing it again with the salt stored in the hash.
Bcrypt only reads the first 72 bytes of a password. Long passphrases that start the same will match each other, so apps that allow very long passwords often pre-hash them (as Django’s bcrypt_sha256 does) or use Argon2id.
Anatomy of a bcrypt hash
| Part | Example | Meaning |
|---|---|---|
| Prefix | $2b$ | Bcrypt version — $2a$, $2b$ and $2y$ are interchangeable for normal passwords |
| Cost | 12$ | 2¹² = 4,096 rounds |
| Salt | R9h/cIPz0gi.URNNX3kh2O | 22 characters = 16 random bytes |
| Checksum | PST9/PgBkqquzi.Ss7KIUgO2t0jWMUW | 31 characters = 23 bytes of the result |
FAQ
Frequently asked questions
Can a bcrypt hash be decrypted?
What cost should I use?
What is the difference between $2a$, $2b$ and $2y$?
Why does the same password give a different hash every time?
Why doesn’t my hash verify?
Is it safe to type a real password here?
Keep going
Related tools
Password Generator
Generate strong, random passwords, memorable passphrases and PINs with a cryptographically secure generator. Free, instant and private — nothing is stored.
Password Strength Checker
Check how strong a password is: time to crack, common words and patterns it hides, tips to improve it, and a safe data-breach check. Fully private.
Hash Generator
Generate MD5, SHA-1, SHA-256, SHA-512, SHA-3, BLAKE3, CRC32 and HMAC hashes of text or files, and verify checksums. Free, fast and private — no upload.
HMAC Generator
Generate HMAC-SHA256, SHA-512, SHA-1 or MD5 in hex or Base64, and verify GitHub, Stripe, Slack, Shopify and Razorpay webhook signatures. Private, no upload.
JWT Debugger
Decode any JWT and verify its signature in your browser: header, claims and expiry explained; HS256, RS256, ES256 and EdDSA with PEM or JWK keys. No upload.
SSL Checker
Check any website’s SSL certificate: expiry date and days left, issuer, covered domains, revocation and CAA, plus a live HTTPS test from your browser.
Last updated Report a problem or suggest a feature