Bcrypt Hash / Verify
Hash a password with bcrypt, or verify a password against an existing hash — locally in your browser.
Hash or verify
Mode
Hash
Create a bcrypt hash from the password
Verify
Check a password against an existing hash
Input
Result
How to Use
Choose Hash to create a bcrypt string, or Verify to check one.
Enter the password. For Verify, also paste a hash starting with $2.
Create the hash or check the match. Hashing is intentionally slow.
Copy the hash if you need it. Nothing is uploaded.
Bcrypt at a glance
Hash
Turns a password into a $2 string. Slow on purpose — that is the point.
Verify
Reports whether a password matches an existing bcrypt hash.
Stays on this device
The password never leaves this tab. Use Hash Generator for SHA checksums, not passwords.
Your passwords stay private.
Bcrypt hashing and verify run locally in your browser. Nothing is uploaded to our servers.
About hashing passwords with bcrypt in the browser
Bcrypt Hash turns a password into a $2 string, or verifies a password against an existing hash, using bcryptjs in this tab. Hashing is intentionally slow (10 rounds). Choose Hash or Verify, then Create hash or Check match. This is explicit work, not a live useMemo on every keystroke, because bcrypt is meant to be expensive. Nothing is uploaded. Do not paste production passwords on a shared machine.
Bcrypt is not SHA-256. Hash Generator is for checksums. HMAC Generator is for keyed authenticity, not password storage. A $2a / $2b prefix is the usual bcrypt family; we are not argon2 or scrypt. 10 rounds is a common default, not a guarantee against future hardware. Verify reports a match or not; it does not “decrypt” a hash.
Related: Password Generator to create a secret first. Password Strength to score a string you typed. JWT Encoder if you needed a token, not a password hash. Close the tab to drop the password from memory.
What is bcrypt?
Bcrypt is a slow password hash. The extra work makes guessing passwords expensive. Toolora uses 10 rounds, which is a common default.
Learn moreCommon Use Cases
Store password hashes in an app
Check a login against a saved $2 hash
Migrate or debug bcrypt hashes locally
Avoid sending passwords to a remote hasher
Is hashing uploaded?
No. Hashing and compare run in this browser with bcryptjs. Keep production passwords off shared machines.
Learn moreRelated password tools
Password Generator
Generate strong random passwords instantly in your browser. Free, private, and no signup required.
Password Strength Checker
Estimate password strength from length and character variety. The score updates as you type.
Hash Generator
Generate SHA-1, SHA-256, SHA-384, or SHA-512 hashes using various encodings. Hashing is commonly used to verify integrity and fingerprint data.
HMAC Generator
Generate HMAC (Hash-based Message Authentication Code) using various algorithms. HMAC is commonly used to verify the integrity and authenticity of messages.
JWT Encoder
Sign an HS256, HS384, or HS512 JWT locally from a JSON payload and secret.
Bcrypt Hash / Verify FAQ
Enter the password, choose Hash, and create the hash. Hashing is intentionally slow (10 rounds) and is a click, not a live keystroke hash. Nothing is uploaded.
Choose Verify, paste the password and the $2 hash, then check the match. Toolora reports whether they match. It does not decrypt a hash.
No. Hash Generator is for checksums. HMAC is keyed authenticity, not password storage. Do not paste production passwords on a shared machine. Close the tab to drop them.