Developer

Bcrypt Generator

Generate secure Bcrypt hashes with custom cost factors.

Last reviewed by the Radiatus Cloud team

Need this built for your product?

We design, build & host secure software & APIs.

Talk to an engineer

Generate bcrypt password hashes

Bcrypt is a widely-used password-hashing algorithm designed to be slow enough to resist brute force. This tool generates secure bcrypt hashes with a custom cost factor, so you can produce properly hashed passwords or test against a hash.

Why bcrypt and the cost factor

Passwords must be stored as slow, salted hashes, never plain text or fast hashes, so that an attacker who steals the database cannot crack them quickly. Bcrypt is built for this, and its cost factor controls how slow it is: each increment roughly doubles the work, so you tune it to be as slow as your server can tolerate, making brute force expensive. A well-chosen cost factor is what keeps bcrypt strong as hardware improves. Bcrypt also builds the salt into the hash, so identical passwords hash differently, defeating precomputed attacks.

Best-practice password hashing

It runs entirely in your browser, so nothing you paste is uploaded and the result is yours to copy straight into a project. Because it works client-side, you can use it on private code and data without anything leaving your machine.

Related tools

  • JSON Formatter — Format and beautify JSON in your browser. Pinpoints syntax errors by line and column, flags unsafe integers, and never uploads your data to a server.
  • JSON Validator — Validate JSON syntax with precise line and column errors, and check documents against a JSON Schema. Runs locally in your browser, nothing uploaded.
  • Regex Tester — Test regular expressions against sample text with live match highlighting, capture groups and flag control. Runs entirely in your browser.
  • HTML Minifier — Minify HTML by removing comments and redundant whitespace, without breaking inline elements or pre blocks. Runs entirely in your browser.

Frequently Asked Questions

What is the cost factor?

A number controlling how slow bcrypt is. Each increment roughly doubles the work, so you tune it to be as slow as your server tolerates, making brute force expensive.

Why must password hashing be slow?

So that an attacker who steals the hashes cannot try billions of guesses quickly. A deliberately slow hash makes cracking impractical.

Does bcrypt use a salt?

Yes. It builds a unique salt into each hash, so identical passwords produce different hashes, which defeats precomputed-table attacks.

How do I choose a cost factor?

Set it as high as your server can tolerate for the login time you accept, and raise it over time as hardware gets faster.

Is my password uploaded?

No. The hashing runs entirely in your browser.

Privacy & Security

Runs in your browser. Nothing you enter is uploaded or stored.

Data: None
Server-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.