BCRYPT
Generate and verify bcrypt password hashes in your browser. Adjustable cost factor, salt randomness demo, zero server round-trips.
Bcrypt is a battle-tested password hashing function designed for secure password storage. Unlike fast algorithms (MD5, SHA-1), bcrypt is intentionally slow and adaptive — making brute-force attacks expensive even as hardware improves.
Why three hashes look different
Bcrypt automatically generates a unique random salt for each hash and embeds it in the output string. Two hashes of the same password will always look different, yet both verify correctly. This eliminates pre-computed rainbow table attacks.
Reading a bcrypt hash
$2b$10$N9qo8uLOickgx2ZMRZoMyeIjZAgcfl7p92ldGxad68LJZdL17lhWy │ │ └─ 22-char salt + 31-char hash │ └─ cost factor (10 = 2^10 iterations) └─ algorithm version (2b)
Choosing a cost factor
- 10–12 — recommended for most web apps (100–400ms)
- 13–14 — high-security use cases (accept slower UX)
- 4–8 — testing/development only
Security and Privacy
All hashing runs in your browser via the bcryptjs library. Your plaintext
and hashes never leave your device. Safe to use with real passwords, though test data is
always a good habit.