Skip to content

Bcrypt Generator & Verifier

Generate bcrypt password hashes with an adjustable cost factor and verify a password against an existing hash, using the bcryptjs library.

Bcrypt Generator & Verifier

10

210 = 1,024 key-expansion rounds — balanced — common default for servers.

Generate a hash to see it here.

Hashing runs entirely in your browser, which is great for testing and learning — but it is not a replacement for server-side hashing during real authentication. Never send plaintext passwords to the client to hash them there. Raising the cost factor strengthens the hash but slows every login by design.

Updated . Provided as is. Check the output before you rely on it in production.

How to use Bcrypt Generator & Verifier

  1. 1

    Enter the password to hash

    In Hash mode, type the password you want to protect. The tool produces a standard bcrypt string beginning with $2 that already contains its own random salt.

  2. 2

    Set the cost factor

    Drag the cost slider between 4 and 15. Higher values strengthen the hash against cracking but make each hash slower to compute, which the readout explains as you adjust it.

  3. 3

    Generate and copy the hash

    Run Generate Hash, wait through the brief loading state at high cost factors, then copy the result for storage, seeding, or a test fixture.

  4. 4

    Verify an existing hash

    Switch to Verify, paste a bcrypt hash and a candidate password, and check whether they match before relying on the credential.

Questions and answers

What does this bcrypt tool do?
bcrypt is a deliberately slow password-hashing function that stores a random salt and a cost factor inside each hash, so leaked hashes resist brute force. This tool hashes a password at the cost you choose with the bcryptjs library and checks whether a plaintext password matches an existing hash.
Which cost factor should I choose?
Each step doubles the work. 10 is a common server default; 12 is stronger but noticeably slower. Pick the highest value your login latency budget tolerates, since a slower hash is harder to brute force.
How do I verify a password against a hash?
Switch to Verify, paste the stored bcrypt hash, type the password to check, and run it. The tool reports a clear match or no-match using a constant-time comparison from the bcrypt library.
Is this safe to use for real authentication?
Use it for testing, learning, and generating sample hashes. Production logins should hash on the server. Never send a user's plaintext password to the browser to be hashed there.
Does my password leave the browser?
No. Hashing and verification run client-side with the bcryptjs library. Passwords and hashes stay in the page and are never transmitted.
For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Browser workflow

Runs instantly in the browser with private local processing and copy/export-ready output.

Browser Workflow

This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.

/bcrypt-generator/

For automation planning, fetch the canonical contract at /api/tool/bcrypt-generator.json.