Higher = slower + more secure. Cost 12 takes about 4ms on a typical laptop; 10-12 is the common production range.
Runs 100% in your browser - the password and hash never leave your device.
I am storing user passwords for a web app with at most 10 000 users. Compare bcrypt (cost 12), scrypt, and Argon2id for this workload: resistance to GPU cracking, memory requirements, DoS risk on the login endpoint, and the parameters you would actually deploy. Give a concrete recommendation and the exact parameter values.
(문서는 영어)
What it does
Bcrypt
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
& Verify hashes a password with bcrypt - the algorithm purpose-built for storing passwords - and checks a password against an existing bcrypt hash. Hashing derives a fresh 16-byte randomsaltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
and runs the EksBlowfish key schedule2^cost times, so you control exactly how expensive each guess is. Verifying recomputes the digest with the hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
’s ownsaltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
and cost and tells you whether it matches. It accepts$2a$, $2b$ and $2y$ hashes, so it works with hashes produced by Node, Go, Python, PHP, Java, PostgreSQL’s pgcrypto and every OpenBSD-derived implementation.
Everything runs in your browser, from a from-scratch Blowfish implementation (no external crypto library). The password you type and the
hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
you paste never leave your device.How to use it
- Pick a mode with the
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
/ Verify toggle at the top. HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
: type the password (the eye button reveals it), drag the cost factor slider (4-16, default 12) - higher means slower and more secure - then pressHashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
password. The$2b$hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
appears with a copy button and a badge showing how long it took.- Verify: paste the bcrypt
hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
and type the password to check. The tool decodes the hash live and shows its version, cost andsaltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
. Press Verify password to get a green Match ✓ or red No match ✗ badge. - Use Sample in either mode to load example inputs (the verify sample is a real matching pair).
Examples
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
Password: HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.correct horse battery staple → press
$2b$12$9IZSN8TXXnSIx4aI0Cd2DetqQ/3FT9d6KJ9fl96SnULIK5x5q/moq
Every run produces a different
hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
- thesaltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
is freshly random each time - and all of them will verify against the same password.Verify a hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
Paste $2a$04$RPx7yiCLNb09VKAUBVNsnOVNzB1Zp/hE1qbDvGUs1aehNX5hE15su with password password → Match ✓. The badges decode it as version $2a$, cost 4,
saltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
RPx7yiCLNb09VKAUBVNsnO.
Read the hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
$2b$12$ + 22 characters of
saltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
+ 31 characters of digest = 60 characters total. The12 is the cost: 2¹² = 4 096 EksBlowfish rounds were run to build the key schedule.
Good to know
- Why bcrypt beats plain SHA-256 for passwords: SHA-256 is fast - exactly what you do not want. A modern GPU computes billions of SHA-256 per second but only tens of thousands of bcrypt hashes, because bcrypt’s cost factor forces 2^cost sequential key-schedule rounds and its
saltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
kills rainbow tables and cross-account reuse. For the same reason bcrypt also beats MD5 and SHA-1 outright - both are broken for collisions and far too cheap to compute. - Cost is a dial, not a constant: pick the slowest cost your users and hardware tolerate - roughly 250ms-1s per
hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
on your login servers. Today that means cost 10-12; raise it every few years as hardware speeds up. Verification pays the same cost as hashing, so an absurdly high cost also slows your own logins and can become a denial-of-service lever on the login endpoint. - 72-byte limit: bcrypt reads at most the first 72 bytes of the password and this tool follows that rule exactly. Modern advice is to pre-
hashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
with SHA-256 if you must support long passphrases - but do it carefully (HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
the raw length first, or you inherit SHA-256’s null-byte ambiguities). - Never invent your own comparison: always verify with a constant-time comparison like this tool does - string equality on hashes leaks timing information.
- Alternatives when you can choose: Argon2id (memory-hard, won the Password
HashingHashingA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
Competition) and scrypt are stronger against GPU/ASIC attackers; bcrypt remains a battle-tested, everywhere-supported baseline. - Related tools: Password Strength Analyser, Password Generator, HMAC Generator.