Skip to content
ALL DEVELOPER TOOLS56
JSON FormatterTXT → JSONJSON to CSVJSON → CSVCSV to JSONCSV → JSONSQL FormatterSQL → SQLMarkdown to HTMLMD → HTMLHTML to MarkdownHTML → MDXML FormatterXML → XMLBase64 Encode/DecodeTXT → B64URL Encode/DecodeTXT → URLJWT DecoderJWT → JSONHTML Entity Encode/DecodeTXT → HTMLUUID Generator— → UUIDPassword Generator— → TXTHash GeneratorTXT → HASHLorem Ipsum Generator— → TXTQR Code GeneratorTXT → PNGColor Picker & Converter— → HEXCSS Gradient Generator— → CSSBox Shadow Generator— → CSSRegex TesterTXT → MATCHCron Expression GeneratorTXT → CRONTimestamp ConverterNUM → DATEText DiffTXT → DIFFText Case ConverterTXT → TXTWord CounterTXT → STATSSubtitle ConverterSUBS → SRT · VTT · ASSYAML to JSONYAML → JSONJSON to YAMLJSON → YAMLYAML FormatterYAML → YAMLJSON MinifyJSON → JSONSort & Dedupe LinesTXT → TXTLine Ending ConverterTXT → CRLF · LF · CRXLSX to CSVXLSX → CSVCharset ConverterTEXT → UTF-8HAR ViewerHAR → TABLE · HARJWT EncoderJSON → JWTHMAC GeneratorTXT → MACFile ChecksumFILE → VERDICTWi-Fi QR Code Generator— → QRChmod CalculatorOCTAL → RWXHTTP Status CodesCODE → MEANINGByte ConverterSIZE → UNITSTime Zone ConverterTIME → ZONESAspect Ratio CalculatorSIZE → RATIOURL ParserURL → PARTSExtract ArchiveARCHIVE → FILES · ZIPCreate ZIPFILES → ZIPUnzip FilesZIP → FILESDOCX to MarkdownDOCX → MDSVG OptimizerSVG → SVGBarcode Generator— → BARCODEQR Code ReaderIMG → TEXTVCF to CSVVCF → CSVICS to CSVICS → CSVCSV to Markdown TableCSV → MDBcrypt Generator— → HASH
ENGINE BCRYPTJSACCEPTS NONE

Bcrypt Generator

BCRYPTJSTOOL 190 OF 190

Bcrypt Generator and Checker

Hash a password with bcrypt at a work factor you choose, or verify one against a hash you already have.

ENGINEBCRYPTJS
ACCEPTSNONE
MAX SIZENONE
UPLOADNEVER
01Type or paste the password into the field at the top of the page.
02Set the work factor — each step doubles the time, for you and for an attacker.
03Press Generate hash, then Copy the result.

About Bcrypt Generator

Bcrypt is what you store instead of a password. Unlike SHA-256 or MD5 it is deliberately slow and it salts every hash, and both of those properties exist to make a stolen database worth less. The salt means two people with the same password get different hashes, so a precomputed lookup table is useless. The slowness means an attacker testing billions of guesses pays the same multiplier you did — which is why the work factor is the only setting that matters here, and why each step of it doubles the cost rather than adding to it. Ten is what most frameworks default to and twelve is the common current advice; this page stops at fourteen, because beyond that the tab freezes for long enough that people assume it has crashed. The page shows how long your hash actually took on your own machine, which is a far better guide than any general recommendation. A bcrypt hash carries its own version, work factor and salt inside those sixty characters, which is why checking a password needs nothing but the hash itself — there is no separate salt to store and no configuration to remember. The checker here reports three outcomes rather than two: match, no match, and 'that is not a bcrypt hash'. Collapsing the third into the second is a common shortcut and it is a bad one, because it tells someone their password is wrong when what is actually wrong is the thing they pasted. Everything runs in your tab. That matters more here than on most pages, because using an online bcrypt tool means typing a real password into someone else's website; this one has nowhere to send it.

Questions

Is my password sent anywhere?

No, and that is the reason to use this one rather than the first result on a search. Hashing happens in your tab — there is no request carrying the password, no server-side hashing, and no log. Every online bcrypt tool that hashes on its server has, by definition, seen the plaintext of whatever you typed. If the password is one you actually use somewhere, that distinction is the whole thing.

What work factor should I use?

Ten is what most frameworks default to and twelve is the common current advice, but the number that should decide it is the one this page shows you: how long the hash actually took on your own machine. Each step DOUBLES the work, so twelve is roughly four times ten, not twenty per cent more. Pick the highest cost your server can afford at your login rate — the same multiple falls on anyone attacking a stolen database.

Why does the same password give a different hash every time?

Because bcrypt generates a fresh random salt for each hash, and the salt is stored inside the result. That is the property that makes bcrypt worth using: two people with the same password get different hashes, so an attacker cannot precompute a lookup table or spot that two accounts share a password. Both hashes still verify against the original password — the checker on this page will confirm it.

Why does the page freeze at high cost settings?

Because bcrypt is deliberately expensive and the work happens on the page's own thread. That is the algorithm doing exactly what it is for, not a hang, and the page says so before it starts. The slider stops at 14 for this reason: each further step doubles the wait, and past that point a browser tab looks broken rather than busy.

Can I check a password against a hash I already have?

Yes — paste the hash into the checker in the sidebar and it will compare it against the password in the field above. It reports three outcomes, not two: match, no match, and 'that is not a bcrypt hash'. The third exists because collapsing it into 'no match' tells you your password is wrong when what is actually wrong is the string you pasted, which wastes a great deal of time.

Is bcrypt still the right choice?

For most applications, yes — it is well understood, available everywhere, and correctly used it is a sound default. Argon2id is the current recommendation where you can choose freely, because it resists GPU and custom-hardware attacks better, and scrypt sits between them. What matters far more than the choice between them is not using a fast general-purpose hash: SHA-256 and MD5 are designed to be quick, which is exactly the wrong property for a stored password.

Is my file uploaded to a server?

No. Transmute processes everything locally in your browser using JavaScript and WebAssembly. Your files never leave your device — there is no server, no upload, no cloud processing.

Related