By ToolzHive
About this tool
Bcrypt is a password hashing function built to be slow, which makes guessing passwords from a stolen database extremely expensive. Each hash includes a random salt, so the same password gives a different hash every time. This tool creates bcrypt hashes with the cost factor you choose, using PHP's password_hash() like Laravel and WordPress, and checks whether a password matches an existing hash.
How to use Bcrypt Hash Generator
- Enter the text or password and choose a cost factor; 10 to 12 is typical.
- Click Generate hash and copy the result, which starts with $2y$.
- To test a login, enter a password and a hash under "Check a password" and click Check match.
Worked example
Hashing "secret" twice gives two different 60-character strings, both starting with $2y$10$, because each has its own random salt. Yet both verify as a match for "secret".
Checking is not decryption
Verification compares supplied text with a hash. It does not recover the original password. Use the Check match form with sample values when testing a workflow.
Why is the hash different every time?
Bcrypt adds a random 128-bit salt to each hash and stores it inside the result, so identical passwords never share a hash. Verification reads the salt back out.
What cost factor should I use?
Choose the highest cost that keeps hashing under about 250 ms on your server; 10 to 12 is common. Each step up doubles the work.
Is there a password length limit?
Yes. Bcrypt only uses the first 72 bytes of input. The tool warns you if your input is longer.
Server processing
Hash generation and password verification send the entered text and hash to ToolzHive’s server. Use sample credentials rather than passwords you use elsewhere.
Put this guide into practice
- Bcrypt Hash Generator — Create bcrypt password hashes with a chosen cost, and check passwords against a hash.