TechWeirdoTools

Input

12 · 4,096 rounds

Each +1 doubles the work. Pick the highest cost your login latency budget allows.

Result

Hashing runs in this tab with a fresh random salt.

No hash yet

Enter a password and generate a hash, or switch to Verify to check one.

How to hash a password with bcrypt

  1. Enter or generate a password

    Type the password, or use the suggestion button for a strong random one. The counter shows UTF-8 bytes, because bcrypt only reads the first 72.

  2. Choose a cost factor

    Cost 12 is a sensible default in 2026. Every step up doubles the time to hash — and the time an attacker needs per guess.

  3. Generate and copy

    The hash includes the algorithm version, cost and salt, so you can store this single string in your database.

How a bcrypt hash is structured

A bcrypt hash is a 60-character string that packs everything needed to verify a password later:

$2b$Version 12$Cost (2¹² rounds) R9h/cIPz0gi.URNNX3kh2OSalt · 22 chars PST9/PgBkqquzi.Ss7KIUgO2t0jWMUWHash · 31 chars

Because the salt is random, hashing the same password twice gives different strings — both are valid. To verify, bcrypt re-hashes the candidate password with the stored salt and cost and compares the result in constant time. Bcrypt is one-way: a hash cannot be “decrypted” back into the password.

Bcrypt vs Argon2, scrypt and SHA-256

Fast hashes like SHA-256 or MD5 are designed for speed, which makes them easy to brute-force; never use them alone for passwords. Bcrypt, scrypt and Argon2id are deliberately slow and salted. OWASP currently recommends Argon2id first, then scrypt, with bcrypt (cost 10 or higher) as a widely supported, battle-tested choice.

Verify in your code

// Node.js (bcryptjs or bcrypt)
const ok = await bcrypt.compare(password, storedHash);

# Python (bcrypt)
ok = bcrypt.checkpw(password.encode(), stored_hash.encode())

// PHP
$ok = password_verify($password, $storedHash);

Frequently asked questions

Does this bcrypt generator upload my password?

No. Hashing and verification run in JavaScript inside this browser tab. The password is never sent to TechWeirdo or anyone else.

What bcrypt cost factor should I use?

Start at 12 and benchmark on your production hardware: choose the highest cost that keeps a login under roughly 250 ms. OWASP’s minimum is 10. Re-hash passwords with a higher cost when users next sign in.

Why does the same password produce a different hash each time?

Each hash uses a new random 128-bit salt. That is expected and prevents attackers from using precomputed tables. Verification still works because the salt is stored inside the hash.

Can a bcrypt hash be decrypted?

No. Bcrypt is a one-way function. The only way to recover a password is to guess candidates and hash each one, which a high cost factor makes slow and expensive.

What is the difference between $2a$, $2b$ and $2y$?

They are bcrypt versions. $2b$ is current and fixes a length-handling bug in old $2a$ implementations; $2y$ is PHP’s equivalent. Modern libraries verify all three.

Why is there a 72-byte limit?

Bcrypt’s key setup only uses the first 72 bytes of input. Emoji and many non-Latin characters take 2–4 bytes in UTF-8, so the counter measures bytes rather than characters.