Hash and verify passwords with bcrypt or salted SHA in-browser.
⏱️ ≈ ~100 ms per hash on a typical desktop
⚠️ This is a client-side demo: hashing runs locally in your browser and nothing is uploaded. In production, hash passwords server-side with a dedicated password-hashing algorithm — argon2id or bcrypt — never with a bare SHA-2 hash. Salted SHA-256/SHA-512 is included here for learning and legacy-format verification only.
This tool turns a password into a bcrypt hash (or a salted SHA-256/SHA-512 digest) and can verify a password against an existing hash — all 100% in your browser, with nothing sent over the network. It is useful for checking what a stored hash really contains, generating a hash for a config file or a seeded test user, or learning how password hashing parameters behave before wiring them into a backend.
bcrypt is a deliberately slow, adaptive password hash built on the Blowfish cipher. Each hash embeds everything needed to verify it: the version ($2a$/$2b$), the cost factor, and a 16-byte random salt — so a bcrypt string like $2a$10$N9qo8uLOickgx2ZMRZoMye… is fully self-describing. Slowness is the feature: an attacker who steals your database must pay the same expensive computation for every guess, which makes bulk cracking of strong passwords impractical. Salts are generated automatically per hash, so two users with the same password still get different hashes.
The cost factor is exponential: 2^cost iterations, so every step doubles the work for you and for an attacker. 10–12 is the common sweet spot today — pick the highest value that keeps your login flow comfortably fast on your production hardware, then revisit it every year or two as machines get faster. Values above 12 are noticeably slow in a browser tab (this tool warns you), which is exactly the resistance you want against offline cracking. Note that bcrypt only reads the first 72 bytes of a password; anything beyond that is silently ignored by design.
A salted SHA-2 digest (sha256$salt$hash) stops rainbow tables and identical-password collisions, but SHA-2 is built for speed — a GPU can test billions of candidates per second, so it is not suitable for storing real user passwords on its own. Use the SHA options here for learning, checksums, or verifying legacy formats; for anything that protects actual accounts, hash server-side with argon2id or bcrypt (or at minimum PBKDF2 with a high iteration count), keep the hashes server-side too, and never log plaintext passwords. This page never transmits what you type — but your production system should not trust client-side hashing either.
The Bcrypt Hash Generator creates bcrypt generator on demand, right in your browser. Set the options you need, click generate, and the result is ready to copy. Because everything runs locally, nothing you enter or produce leaves your device.
Generators like this are useful when you need a specific output (a password, a UUID, a QR code, placeholder text) and don't want to install an app or trust an unknown website with your data. This tool is free, has no usage limits, and works the same on phone and desktop.
Common uses: people reach for this tool when they need to use a bcrypt hash generator with salt rounds, verify bcrypt hash online, password hashing tool for developers, or bcrypt cost factor explained.
Browser-based tools like this one have a few real advantages over installed software or manual methods:
More tools you might find useful