BasicApps Logo
Bcrypt Password Hash Generator

Generate secure bcrypt password hashes with customizable salt rounds

Generate Bcrypt Hash

Fast (4)Balanced (12)Secure (20)
Security Level: Strong - Excellent security

Verify Password

Enter password and hash to verify automatically

Bcrypt Security Tips

  • • Salt Rounds: Use 10-12 rounds for most applications, 12-15 for high-security
  • • Performance: Higher rounds = more secure but slower (test on your hardware)
  • • Future-Proof: You can increase rounds over time as hardware improves
  • • Never Store: Never store plain text passwords, always hash them
  • • Unique Salts: Bcrypt automatically generates unique salts for each hash

The cost factor is the only setting that actually matters

Most people leave it at 10 and move on. That's reasonable. Cost 10 takes roughly 65ms on a modern CPU — slow enough to make brute-force expensive but fast enough that a login endpoint handles it without noticeable lag. If you're on older hardware or expecting high login volume, test at 10 first before going higher. Cost 12 is about four times slower, closer to 260ms, which is the better default for most production auth systems today. The hash is always 60 characters, always starts with $2b$, and those two digits right after it are the cost factor. The next 22 characters are the salt, and the final 31 are the digest. The salt is random on every hash, which is why hashing the same password twice gives different output.

The Verify tab is actually the more useful half of this tool

When you're debugging an auth system or migrating passwords between services, you usually have a stored hash and need to confirm whether a password matches it. Paste both into the Verify tab and it runs the comparison correctly — re-hashing the candidate with the salt extracted from the existing hash, then comparing in constant time. That's exactly what bcrypt.compare() does in application code; the tab just saves you from writing a throwaway script to test it. One thing worth knowing: bcrypt silently truncates input at 72 bytes. Passwords longer than that all hash identically past that point. For very long passphrases where that truncation would matter, Argon2 handles it without the limit.