Security

Bcrypt Generator

Generate and verify bcrypt password hashes, with cost factors, the salt handling and bcrypt's known limitations.

Last reviewed by the Radiatus Cloud team

Bcrypt Hash Generator

Generate and verify secure Bcrypt password hashes locally.

Generate Hash
Verify Hash

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Why bcrypt and not a fast hash

General-purpose hashes such as SHA-256 are designed to be fast, which is exactly wrong for passwords: modern hardware computes billions per second, so a stolen table of unsalted SHA-256 hashes is cracked at enormous rates. Bcrypt is deliberately slow and its cost is adjustable, so it can be made to stay slow as hardware improves.

The salt is inside the hash

Bcrypt generates a random salt per password and embeds it in the output string alongside the algorithm identifier and cost factor. You do not store the salt separately, and you must not reuse one. This is why hashing the same password twice produces two different strings, and why verification takes the stored hash rather than requiring you to recover the salt yourself.

Cost factor

The cost is a power of two: raising it by one doubles the work. A cost of 12 is a reasonable current default on server hardware, taking roughly a quarter of a second. Too low and cracking is cheap; too high and your login endpoint becomes a denial-of-service target against yourself. Benchmark on your actual hardware and revisit every couple of years.

The 72-byte limit

Bcrypt silently ignores anything past 72 bytes of input. A long passphrase is truncated, so two passwords sharing their first 72 bytes hash identically. It also means pre-hashing a password with SHA-256 and base64-encoding the result can exceed the limit if done carelessly. Where very long passwords matter, Argon2id has no such restriction.

Argon2id is the current recommendation

Bcrypt remains acceptable and widely deployed, but Argon2id is memory-hard, which resists GPU and ASIC attacks far better than bcrypt's modest memory use. For new systems Argon2id is the better default, with bcrypt and scrypt as accepted alternatives. Migrating is straightforward: rehash on next successful login.

Never hash a real password in a web tool

This includes this one. Use it to understand the format or to generate a test fixture. Production hashing belongs in your application with a vetted library.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

Why not use SHA-256 for passwords?

Because it is fast by design, and modern hardware computes billions of digests per second. Password hashing needs to be deliberately slow and adjustable, which is what bcrypt provides.

Do I need to store the salt separately?

No. Bcrypt generates a random salt per password and embeds it in the output alongside the algorithm and cost. That is why the same password hashes differently each time.

What cost factor should I use?

Around 12 on current server hardware, taking roughly a quarter of a second. Each increment doubles the work. Too high turns your login endpoint into a self-inflicted denial-of-service target.

What is bcrypt's 72-byte limit?

Input beyond 72 bytes is silently ignored, so two passwords sharing their first 72 bytes hash identically. Argon2id has no such limit if very long passphrases matter to you.

Should I use bcrypt or Argon2id?

Argon2id for new systems, since it is memory-hard and resists GPU and ASIC attacks far better. Bcrypt remains acceptable and widely deployed; migrate by rehashing on next successful login.

Privacy & Security

Local hashing.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.