Bcrypt Generator & Verifier
Hash a password with bcrypt (adjustable cost) and verify a password against an existing bcrypt hash. Runs on the server for that request only; nothing is stored.
Generate a bcrypt hash
Verify a password against a hash
Your input is processed on the server for that one request only. Nothing is stored, and passwords are never echoed back into the page.
How to use the bcrypt generator & verifier
- Generate: type a password, choose a cost (higher is slower and stronger; 12 is a good default), and click Generate hash. Copy the resulting
$2y$...hash into your database. - Verify: paste an existing bcrypt hash and the password you want to test, then click Verify to see whether they match.
Bcrypt hashes are salted and one-way, so the same password produces a different hash each time — and you can never reverse a hash back into the password. That is exactly why hashing the same password twice will not equal an earlier hash, yet Verify still confirms a match.
More PAYATE tools
Frequently asked questions
What is bcrypt?
Bcrypt is a password-hashing function designed specifically for storing passwords securely. It builds a slow, salted one-way hash on top of the Blowfish cipher, so that even if a database leaks, the stored hashes are expensive to crack. Each hash includes its own random salt and the cost factor, which is why the same password produces a different hash every time.
What is the cost factor (work factor)?
The cost (or work factor) is a number that controls how much work bcrypt does. Each step up doubles the time to compute a hash: cost 12 is twice as slow as 11, and four times slower than 10. A higher cost makes brute-force cracking harder but also makes each login slower. Cost 12 is a common modern default; pick the highest value your server can handle in a fraction of a second.
Is bcrypt reversible?
No. Bcrypt is a one-way function — there is no way to decrypt or reverse a hash back into the original password. You can only verify a candidate password by hashing it the same way and comparing, which is exactly what the Verify mode does with password_verify().
Should I use bcrypt for passwords?
Yes. Bcrypt is a solid, widely supported choice for password storage because it is deliberately slow and salted. Argon2 is a strong modern alternative. What you should not do is store passwords with fast, general-purpose hashes like MD5 or SHA-256, which are far too quick to brute-force.
Is my password stored or logged?
No. Your input is sent to the server to compute or verify the hash for that one request only, and nothing is stored in any database or log. The password is never echoed back into the page. Still, avoid pasting a real production password you do not want to transmit.
What is the difference between bcrypt and MD5 or SHA?
MD5 and SHA-256 are fast, general-purpose hashes built for checksums and integrity — that speed makes them a poor choice for passwords, since an attacker can try billions of guesses per second. Bcrypt is deliberately slow and salted, with an adjustable cost, so it is built to resist exactly that kind of brute-force attack.