All tools

Bcrypt Generator

Hash and verify bcrypt passwords

Generate bcrypt hashes with a chosen cost and check a password against an existing hash. It runs in a Web Worker in your browser and nothing is uploaded or saved.

How to use Bcrypt Generator

  1. Choose Generate, type a password and pick a cost (4 to 15). Each step up doubles the work and the time.
  2. Press Generate hash. You get a 60-character hash plus its parts: version, cost, salt and hash.
  3. To check a password, switch to Verify, enter the password and paste an existing $2a$, $2b$ or $2y$ hash.
  4. Copy the hash. A new random salt is used on every run, so the same password gives a different hash each time.

How it works

This is an implementation of bcrypt (EksBlowfishSetup) written for this page. The Blowfish tables are computed from the digits of pi, the key schedule is run 2^cost times with your password and the salt, and the text OrpheanBeholderScryDoubt is then encrypted 64 times. The result is written in bcrypt’s own Base64 alphabet.

The work runs in a Web Worker so the page stays responsive. The 16-byte salt comes from crypto.getRandomValues. Verifying re-hashes with the salt and cost found in the hash and compares in constant time. The time estimates come from a quick cost-4 run on your device, doubled per step.

Limits

  • bcrypt reads only the first 72 bytes of the password, counting a trailing NUL byte, so at most 71 bytes of UTF-8 are used. Longer input is silently cut off; the page warns you.
  • Cost is limited to 4–15. Cost 14 and 15 can take many seconds to minutes in a browser.
  • $2a$, $2b$ and $2y$ are produced and accepted. They give identical hashes; only the prefix differs. $2x$ (the old buggy PHP variant) is not supported.
  • This is JavaScript, far slower than native bcrypt. Use it for testing and tooling, not as a production password service.

Privacy

Everything happens in your browser. Passwords and hashes are never uploaded and are not stored in the page, the URL or browser storage. Closing the tab forgets them.

Frequently asked questions

Which cost should I pick?

Pick the highest cost your servers can bear, aiming for roughly 250 ms to 1 s per hash. 10 to 12 is common today. Re-hash when hardware gets faster.

Why is the hash different every time?

A random salt is generated per hash and stored inside it. Use Verify to check a password; comparing hash strings directly won’t work.

What are $2a$, $2b$ and $2y$?

Version markers. $2b$ is the current OpenBSD form; $2y$ is PHP’s equivalent; $2a$ is the older form. For passwords under 255 bytes they produce the same hash body.

Is it safe to type a real password here?

Nothing leaves the page, but avoid pasting real production passwords into any website out of habit. This tool is best for test values.

More tools