Bcrypt hash generator and checker
Store sign-in passwords the safe way and check a login against the saved hash.
Private: your files never leave this deviceNothing is uploaded or stored on a serverWorks right here in your browserUse it in your code
import bcrypt # pip install bcrypt hashed = bcrypt.hashpw(password.encode(), bcrypt.gensalt(rounds=10)).decode() is_verified = bcrypt.checkpw(password.encode(), hashed.encode())
Uses the cost chosen above. Store the whole 60-character hash in one column; the check reads the version, cost and salt back out of it.
How to generate and verify a bcrypt hash
Type or generate a password
Type the password you want to store, or press Generate for a random password, passphrase or PIN. The hash appears a moment later, already checked against the password.
Choose the cost
Slide the cost to match your app. Higher is slower and safer; 10 or 12 suits most sign-in pages.
Copy, download or verify
Copy the hash, or download it as text, JSON, CSV, .env or SQL. Switch to Verify to check a password against a hash you already have.
Good to know
- Store the whole hash string. The version, cost and salt are part of it, so your app needs no extra column to check a password later.
- Generate makes the password with your browser's cryptographic random source, with the same options as the password generator. Change an option and a new one is made; type in the box and your own text is kept.
- Verify works with hashes from Python, Node.js, PHP and Java. Paste the hash from your database, type the password, and the result shows at once.
- Use bcrypt, not MD5 or SHA-256, for passwords. Fast hashes are made for checksums and can be guessed billions of times a second.
- Untick Include password before you download if the file is going anywhere shared. The SQL export never contains the password.
- Cost 15 takes a few seconds in a browser. The page shows progress, and you can keep typing while it works.
Questions people ask
Why is the hash different every time?
Each hash gets a new random salt, which is stored inside the hash itself. Two hashes of the same password look different, yet both verify, so a stolen database cannot be matched against a table of common passwords.
Which cost should I pick?
Pick the highest cost your server can check in about a quarter of a second. 10 is the common default in Node.js and 12 is the default in Python's bcrypt and Flask-Bcrypt. Each step up doubles the time for you and for anyone guessing.
Will a hash from here work in my app?
Yes. The output is a standard $2b$ hash that Python bcrypt, Flask-Bcrypt, Node bcrypt and bcryptjs, PHP password_verify, Spring Security and Go all accept. Verify also reads $2a$ and PHP's $2y$ hashes.
Why does bcrypt ignore part of my password?
Bcrypt only uses the first 72 bytes of the password. Letters outside English take two to four bytes each, so the limit can arrive sooner than you expect. The page warns when a password goes past it.
Is my password sent anywhere?
No. Generating, hashing and checking all run in your browser, the hashing in a web worker. The password and the hash stay on your device.