Bcrypt Hash Generator Online

Hash a password with bcrypt right in your browser: adjustable cost, automatic salt, hash ready to store. A verifier is included.

Based on Blowfish, proven since 1999. Each unit of “cost” doubles the work. Limits the password to 72 bytes.

Hash (format to store)

—

Verify a password
Encoded hash
Password to test
Enter a hash and a password.

100% local processing, nothing is uploaded

How does it work?

bcrypt hashes a password with a random salt and an adjustable cost: each unit of cost doubles the work required. The resulting hash (“$2b$…”) contains the cost and the salt: it is the only thing to store.

Proven since 1999, bcrypt remains an excellent choice for storing passwords. Note that it only takes the first 72 bytes of the password into account. The computation runs in your browser, in a worker.

Examples

Default cost of 10

With a cost of 10, bcrypt performs 2^10 = 1,024 rounds. A hash looks like $2b$10$N9qo8uLOickgx2ZMRZoMy…: the “10” is the cost, and the next 22 characters are the salt.

Raising the cost

Going from 10 to 12 quadruples the computation time (2 doublings). The cost is tuned so that a hash takes about 250 ms on the server hardware, a good balance between security and latency.

Frequently asked questions

Why does the computation take several seconds?
That is intentional. These functions are designed to be slow and resource-hungry, so that an attacker who stole the database can only test very few passwords per second. The computation runs in a worker: the page stays responsive.
Do I need to store the salt separately?
No: the salt is included in the encoded hash (the full “$…” string). To verify a password later, you only need to keep that string; it contains the salt and the parameters.
Is my data sent anywhere?
No. All the computation happens in your browser, in JavaScript and WebAssembly. Your text, your files and your hashes never leave your device: no network request is made during hashing, and nothing is stored on a server.