Bcrypt Hash Generator

Securely generate Bcrypt hashes or verify passwords against existing hashes.

Generate Hash

Verify Hash

About Bcrypt

Bcrypt is a robust, adaptive password hashing function based on the Blowfish cipher. It is designed to be slow and computationally expensive, which protects against brute-force attacks and rainbow table lookups.

How to Use

  1. To Hash: Enter a password and specify the "Work Factor" (rounds). A higher work factor means it takes longer to generate the hash, increasing security. Click "Generate".
  2. To Verify: Enter a plain-text password and an existing Bcrypt hash. Click "Verify Match" to check if they correspond.

Features & Security

  • Built-in Salt: Bcrypt automatically generates a unique salt for each hash, meaning the same password will result in a different hash every time.
  • Client-Side Only: All hashing and verification happens locally in your browser. Your passwords are never sent to a server, ensuring maximum privacy and security.

FAQ

Why do the hashes for the same password look different?

Because Bcrypt automatically generates a random salt and incorporates it into the final hash output. When verifying, the algorithm extracts this salt to compute the comparison.

What is the optimal Work Factor?

A work factor of 10-12 is standard for modern applications. The goal is to make hashing take around 250-500ms on a typical server, frustrating attackers without slowing down legitimate logins.