Bcrypt Generator
Generate secure Bcrypt hashes with custom cost factors.
Last reviewed by the Radiatus Cloud team
Need this built for your product?
We design, build & host secure software & APIs.
Generate bcrypt password hashes
Bcrypt is a widely-used password-hashing algorithm designed to be slow enough to resist brute force. This tool generates secure bcrypt hashes with a custom cost factor, so you can produce properly hashed passwords or test against a hash.
Why bcrypt and the cost factor
Passwords must be stored as slow, salted hashes, never plain text or fast hashes, so that an attacker who steals the database cannot crack them quickly. Bcrypt is built for this, and its cost factor controls how slow it is: each increment roughly doubles the work, so you tune it to be as slow as your server can tolerate, making brute force expensive. A well-chosen cost factor is what keeps bcrypt strong as hardware improves. Bcrypt also builds the salt into the hash, so identical passwords hash differently, defeating precomputed attacks.
Best-practice password hashing
It runs entirely in your browser, so nothing you paste is uploaded and the result is yours to copy straight into a project. Because it works client-side, you can use it on private code and data without anything leaving your machine.
Related tools
- JSON Formatter — Format and beautify JSON in your browser. Pinpoints syntax errors by line and column, flags unsafe integers, and never uploads your data to a server.
- JSON Validator — Validate JSON syntax with precise line and column errors, and check documents against a JSON Schema. Runs locally in your browser, nothing uploaded.
- Regex Tester — Test regular expressions against sample text with live match highlighting, capture groups and flag control. Runs entirely in your browser.
- HTML Minifier — Minify HTML by removing comments and redundant whitespace, without breaking inline elements or pre blocks. Runs entirely in your browser.
Frequently Asked Questions
What is the cost factor?
A number controlling how slow bcrypt is. Each increment roughly doubles the work, so you tune it to be as slow as your server tolerates, making brute force expensive.
Why must password hashing be slow?
So that an attacker who steals the hashes cannot try billions of guesses quickly. A deliberately slow hash makes cracking impractical.
Does bcrypt use a salt?
Yes. It builds a unique salt into each hash, so identical passwords produce different hashes, which defeats precomputed-table attacks.
How do I choose a cost factor?
Set it as high as your server can tolerate for the login time you accept, and raise it over time as hardware gets faster.
Is my password uploaded?
No. The hashing runs entirely in your browser.
Privacy & Security
Runs in your browser. Nothing you enter is uploaded or stored.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
JSON Formatter
DeveloperFormat and beautify JSON in your browser. Pinpoints syntax errors by line and column, flags unsafe integers, and never uploads your data to a server.
JSON Validator
DeveloperValidate JSON syntax with precise line and column errors, and check documents against a JSON Schema. Runs locally in your browser, nothing uploaded.
Regex Tester
DeveloperTest regular expressions against sample text with live match highlighting, capture groups and flag control. Runs entirely in your browser.