About this tool
bcrypt is the password-hashing method behind countless logins: instead of storing your password, a website stores a scrambled “hash” that is deliberately slow to make. This tool makes those hashes and checks them. Use “Generate hash” to turn a password into a $2b$, $2y$ or $2a$ hash at the cost you choose, or “Check a password” to find out whether a password matches a hash you already have, such as one from a test database or a config file.
It is built for developers who want to seed a user table, test a login, or understand why a hash looks the way it does. Every hash is split into its four parts, version, cost, salt and checksum, with a plain explanation of each, and the tool times the work on your own device so you can pick a sensible cost. It also warns you when a password runs past bcrypt’s 72-byte limit, a detail most online generators never mention.
Pasting a real password into a website should make you nervous, so this one does all its work in your browser. The bcrypt code was written for this tool, checked against the published OpenBSD and jBCrypt test hashes, and runs in a background worker so the page stays responsive. Nothing is uploaded, logged or stored.
How to use Bcrypt Generator & Checker
- Choose “Generate hash” or “Check a password” at the top.
- To make a hash, type the password, drag the Cost slider (10 is the usual choice) and pick a version: $2b$ for most languages, $2y$ for PHP.
- Press “Generate hash” or Enter. The hash appears with the time it took, and “Copy hash” puts it on your clipboard. “New salt” makes a fresh one.
- To check, type the password and paste the hash. The answer, match or no match, appears as you type, with each part of the hash explained below.
The password “abc” with the salt If6bvum7DFjUnE9p2uDeDu at cost 6 gives $2a$06$If6bvum7DFjUnE9p2uDeDu0YHzrHM6tf.iqN8.yx.jNN1ILEf7h0i, one of the official test hashes this tool is checked against.
Features
- Generate bcrypt hashes at any cost from 4 to 15, with a live estimate of the time on your device after the first hash.
- Check a password against any $2a$, $2b$ or $2y$ hash, at any cost from 4 to 31, with the answer shown as you type.
- Hash anatomy: version, cost, salt and checksum shown in colour, with what each one means and the salt in hexadecimal.
- A fresh 16-byte salt from your browser’s secure random generator (crypto.getRandomValues) for every hash.
- An honest 72-byte counter that tells you when part of a long password is being ignored, and which part.
- Full Unicode support: passwords are turned into UTF-8 bytes first, the same as PHP, Node and Python.
- Plain-English problems for pasted hashes: wrong length, cut-off copies, other hash types such as Argon2.
- Runs in a background worker, with a progress bar for slow costs, so the page never freezes.
Tips and good to know
- For a real server, pick the highest cost that keeps a login under about a quarter of a second on that server. Cost 10 to 12 is typical today; this page times it on your device, which may be faster or slower than your server.
- Each step up in cost doubles the time: cost 15 is 32 times slower than cost 10.
- The same password gives a different hash every time because the salt is random. That is expected; checking still works.
- $2y$ and $2b$ are the same algorithm with different labels. If a library refuses one, changing the label to the other usually works.
- bcrypt reads only the first 72 bytes. For longer passphrases, many systems pre-hash the password (for example with SHA-256) before bcrypt; this tool hashes exactly what you type.
Frequently asked questions
Is my password uploaded or saved anywhere?
No. The hashing runs inside your browser in a background worker. The password is not sent to AroraTools or anyone else, is not saved, and is gone when you close the tab.
Is it free? Are there any limits?
It is free with no sign-up and no limit on how many hashes you make or check. Costs above 15 are not offered for making hashes because they take minutes in a browser, but hashes with higher costs can still be checked.
Does it work on a phone or offline?
Yes. It works in Safari, Chrome and Firefox on phones and computers. Once the page has loaded it needs no connection. Phones are slower, so high costs take longer there.
Why do I get a different hash every time for the same password?
Each hash gets a new random salt, which is stored inside the hash itself. It stops two people with the same password ending up with the same hash. When you check a password, the salt is read back out of the hash, so the result still matches.
What is the difference between $2a$, $2b$ and $2y$?
$2a$ is the older label. $2b$ was introduced by OpenBSD in 2014 after a bug with very long passwords, and $2y$ is the name PHP gave its fixed version. For normal passwords all three give the same checksum, and this tool checks all of them.
What happens to passwords longer than 72 bytes?
bcrypt only uses the first 72 bytes, so anything after that makes no difference: two long passwords that share the first 72 bytes get the same hash. The counter under the password box shows when this happens. Letters with accents and emoji use 2 to 4 bytes each.
Page last reviewed