bcrypt Generator

Hash a password with the bcrypt algorithm and your chosen cost factor. Full implementation runs locally — your password never leaves this page.

Settings

bcrypt Hash ($2a$)

 
 

Anatomy of the Hash

 

Verification Snippets

In Node.js (bcryptjs): bcrypt.compare(password, hash, cb). In PHP: password_verify($password, $hash). In Python (bcrypt): bcrypt.checkpw(password.encode(), hash). In Go (golang.org/x/crypto/bcrypt): bcrypt.CompareHashAndPassword(hash, []byte(password)). These functions parse the cost and salt embedded in the hash automatically.

About bcrypt

bcrypt was designed by Niels Provos and David Mazières in 1999 as an evolution of the Blowfish cipher for password hashing. Its key property is adaptivity: the cost factor means you can keep the hash slow enough that each password guess takes meaningful time, even as CPUs get faster. A random 128-bit salt is included per hash, so identical passwords produce different hashes and rainbow tables are useless. This page implements the full EksBlowfish key schedule, Blowfish encryption rounds and the standard bcrypt Base-64 encoding — the same algorithm used by OpenBSD, Node.js and PHP.