Bcrypt Verify
Check whether a plaintext password matches a stored bcrypt hash.
Verify a password against a bcrypt hash in your browser. Confirm that a plaintext matches a stored bcrypt hash. Free, offline, runs entirely client-side. Read more Show less
What is bcrypt verify?
bcrypt verify takes a plaintext password and a bcrypt hash, recomputes the hash with the same salt and cost that are embedded in the stored hash, and checks whether the two match. It is the same operation every web framework runs when you log in.
This tool is the natural counterpart to the Bcrypt Generator. Use the generator to create a hash, use this tool to prove that a given password matches it.
How to verify
Paste the bcrypt hash and type the password you want to check. The tool returns Match or No match. That is the entire result - bcrypt does not leak why a password did not match, and neither does this tool.
The bcrypt hash format
A bcrypt hash looks like this:
$2b$12$Nk7Vd9wBZL5GJ8pMF.qRhuK3jK8xLmP.oYyZ3XQm5k9fGJ8w5CeZa
The parts are separated by dollar signs:
$2b$ - algorithm version. $2a$, $2b$, and $2y$ are the modern variants. $2$ is the original. All are compatible.
12 - the cost factor. Each increment doubles the work. Cost 10 to 12 is standard for web authentication.
Nk7Vd9wBZL5GJ8pMF.qRhu - 22-character salt, encoded in a custom base64 variant (./A-Za-z0-9).
K3jK8xLmP.oYyZ3XQm5k9fGJ8w5CeZa - 31-character hash of the password salted with the above, also custom base64.
Because the salt and cost are inside the hash string, bcrypt verify needs no other inputs.
FAQ
Why does verification take a moment?
bcrypt is intentionally slow. That is the whole point of choosing it over MD5 or SHA-1. When you paste a hash with cost 12, verify takes 200-400ms on a typical laptop. Cost 14 takes a second or two. Cost 4 is instant - and correspondingly useless for real security.
Can I verify an SHA-1 or MD5 password hash here?
No. Those are fast hashes and you would not need a browser tool to verify them - you would just compute the hash and compare the strings. This tool is specifically for bcrypt hashes with the $2 prefix.
What if I get "not a valid bcrypt hash"?
Three common causes: (1) the hash was truncated during copy-paste, (2) the hash uses a format this tool does not recognize, (3) the input is a salted-MD5 hash from htpasswd ($apr1$...) instead of bcrypt. Check that the hash starts with $2.
Does the cost factor affect verification time?
Yes, and that is by design. Cost 4 verifies in under 100ms. Cost 14 verifies in 1-2 seconds. If verification feels instant, the hash was probably generated with a very low cost.
Is it safe to paste my bcrypt hash into a browser tool?
This tool runs entirely client-side. Nothing is uploaded. But you should never paste a production hash into a random website - always check that the tool loads no network requests after page load, or run a local tool. This page is verifiable in the browser's Network tab if you want to confirm.
What is the difference between verify and "decrypt"?
bcrypt is not reversible. There is no way to recover the plaintext from a bcrypt hash - only to check whether a candidate password matches. If a site claims to "decrypt" a bcrypt hash, it is either brute-forcing it or lying.
Command line equivalent
# Node with bcryptjs
npm i bcryptjs
node -e '
const bcrypt = require("bcryptjs");
const hash = "$2a$12$...";
const password = "hunter2";
bcrypt.compare(password, hash).then(r => console.log(r ? "match" : "no match"));
'
# Python with bcrypt
pip install bcrypt
python3 -c '
import bcrypt
hash = b"$2b$12$..."
password = b"hunter2"
print("match" if bcrypt.checkpw(password, hash) else "no match")
'
# Command line with htpasswd
htpasswd -vb /path/to/.htpasswd username password
# (exits 0 on match, 1 on mismatch)