How to hash a password with bcrypt
Generate or verify a bcrypt password hash locally in your browser with Toolora.
Hash vs verify
Leave the hash field blank to create a bcrypt hash. Paste an existing $2 hash to check whether a password matches. Bcrypt is designed to be slow; that is expected.
Steps
1) Open Bcrypt Hash / Verify at /tools/bcrypt-hash. 2) Enter the password. 3) Optionally paste a hash to verify. 4) Click Run — hashing is intentionally slow. Hashing happens in this browser — we do not store passwords.
Worked example
Hash “correct horse” and you get a $2 string with a salt. Paste that hash plus the same password to verify; a typo fails. SHA Hash Generator is the wrong tool for passwords. Password Generator invents a secret; this page hashes one you already have. Cost/rounds follow the tool’s bcrypt settings — not every server uses the same cost.
Privacy
Passwords stay in the tab. Related: /tools/password-generator, /tools/password-strength. Close the page on a shared PC.
Common mistakes
Hashing with SHA-256 on Hash Generator is not bcrypt; login servers that expect $2a / $2b strings will reject a hex digest. Verify needs the exact hash including the salt prefix. A truncated copy-paste fails. Cost (rounds) may differ from your server — this page is for local checks, not a drop-in of your production KDF. Password Strength Checker does not hash. Close the tab; do not screenshot the password field.