What this does
Paste an encoded password hash and the tool identifies the algorithm, splits out its cost parameters, salt and hash, explains what each one means, and compares them with current OWASP guidance. Nothing is cracked or guessed: it only reads what is written in the string.
Recognised formats
- bcrypt:
$2a$,$2b$,$2x$,$2y$with the cost and the 22-character salt. - Argon2:
$argon2id$,$argon2i$,$argon2d$PHC strings with m, t, p and version. - scrypt:
$scrypt$ln=17,r=8,p=1$.... - PBKDF2: PHC
$pbkdf2-sha256$i=..., passlib$pbkdf2-sha256$rounds$..., and Djangopbkdf2_sha256$iterations$salt$hash. - Unix crypt:
$1$(MD5-crypt),$5$and$6$(SHA-256/512-crypt), inspect only.
Reading the assessment
Green means the settings meet the OWASP Password Storage Cheat Sheet minimums, for example bcrypt cost 10 or more, Argon2id with 19 MiB and 2 passes, scrypt N=2^17 r=8 p=1, or PBKDF2-SHA256 with 600,000 iterations. Red means below those minimums; the fix is to rehash with stronger parameters at the user's next successful login, since a hash cannot be upgraded without the password. Short salts and legacy schemes are flagged too.
Verifying a password
To test whether a password matches a bcrypt, Argon2, scrypt or PBKDF2 hash, use the Verify tab of the password hash generator.
Privacy
The hash is parsed in your browser and never sent anywhere.