Bcrypt Hash / Verify

Bcrypt Hash / Verify

Hash a password with bcrypt, or verify a password against an existing hash — locally in your browser.

Free
No signup
Instant
Private

Hash or verify

Mode
Input

Result

Hash • 0 characters

How to Use

  1. Choose Hash to create a bcrypt string, or Verify to check one.

  2. Enter the password. For Verify, also paste a hash starting with $2.

  3. Create the hash or check the match. Hashing is intentionally slow.

  4. Copy the hash if you need it. Nothing is uploaded.

Bcrypt at a glance

Hash

Turns a password into a $2 string. Slow on purpose — that is the point.

Verify

Reports whether a password matches an existing bcrypt hash.

Stays on this device

The password never leaves this tab. Use Hash Generator for SHA checksums, not passwords.

Your passwords stay private.

Bcrypt hashing and verify run locally in your browser. Nothing is uploaded to our servers.

Learn more about privacy →

About hashing passwords with bcrypt in the browser

Bcrypt Hash turns a password into a $2 string, or verifies a password against an existing hash, using bcryptjs in this tab. Hashing is intentionally slow (10 rounds). Choose Hash or Verify, then Create hash or Check match. This is explicit work, not a live useMemo on every keystroke, because bcrypt is meant to be expensive. Nothing is uploaded. Do not paste production passwords on a shared machine.

Bcrypt is not SHA-256. Hash Generator is for checksums. HMAC Generator is for keyed authenticity, not password storage. A $2a / $2b prefix is the usual bcrypt family; we are not argon2 or scrypt. 10 rounds is a common default, not a guarantee against future hardware. Verify reports a match or not; it does not “decrypt” a hash.

Related: Password Generator to create a secret first. Password Strength to score a string you typed. JWT Encoder if you needed a token, not a password hash. Close the tab to drop the password from memory.

What is bcrypt?

Bcrypt is a slow password hash. The extra work makes guessing passwords expensive. Toolora uses 10 rounds, which is a common default.

Learn more

Common Use Cases

Store password hashes in an app

Check a login against a saved $2 hash

Migrate or debug bcrypt hashes locally

Avoid sending passwords to a remote hasher

Is hashing uploaded?

No. Hashing and compare run in this browser with bcryptjs. Keep production passwords off shared machines.

Learn more

Related password tools

Bcrypt Hash / Verify FAQ

Enter the password, choose Hash, and create the hash. Hashing is intentionally slow (10 rounds) and is a click, not a live keystroke hash. Nothing is uploaded.

Choose Verify, paste the password and the $2 hash, then check the match. Toolora reports whether they match. It does not decrypt a hash.

No. Hash Generator is for checksums. HMAC is keyed authenticity, not password storage. Do not paste production passwords on a shared machine. Close the tab to drop them.