What this does
Generates a bcrypt hash with the cost factor you choose, and verifies a password against an existing $2a$, $2b$ or $2y$ hash. Use the Verify tab to check a hash copied from a database. The result is split into version, cost, salt and hash so you can see what is stored.
Cost factor
The cost is a power of two: cost 12 means 212 = 4,096 rounds of the key schedule, and each increase of one doubles the time. OWASP's minimum is 10; 12 is a sensible default today. The tool caps the cost at 15 because JavaScript is much slower than native bcrypt, so a high cost can take many seconds in the browser. Choose the cost so that hashing takes around 250 ms or more on your production hardware, not in this page.
The 72-byte limit
bcrypt reads only the first 72 bytes of the password (multi-byte characters count per byte). A longer password is truncated without any error, so two long passwords that share their first 72 bytes produce the same hash. This tool warns when it happens. If you need long passwords, pre-hash with SHA-256 and Base64 (with care about NUL bytes), or use Argon2id.
Version prefixes
$2b$ is the current prefix. $2y$ is PHP's name for the same fixed algorithm. $2a$ is the older prefix that behaves identically for ordinary passwords. $2x$ marks hashes from a buggy pre-2011 implementation and cannot be verified here. New hashes are written as $2b$. For other algorithms use thepassword hash generator.
Privacy
The password stays in this tab's memory and is hashed in a background worker. Nothing is uploaded.