Tooleux

Hash a password with bcrypt at a configurable cost factor.

Runs in your browser. Nothing leaves your device.
Hash a password with bcrypt. Free, offline, runs entirely in your browser. Read more Show less

What is bcrypt?

bcrypt is a password-hashing function designed by Niels Provos and David Mazi-res in 1999. It is intentionally slow and uses a configurable cost factor, so hardware improvements can be countered by increasing cost. It also includes the salt in the output, which removes a common class of bugs.

bcrypt is used by many legacy and modern systems. Its 72-byte password limit and 4 KB working memory make it weaker than Argon2 or scrypt against modern GPUs, but it is still acceptable when the cost factor is set appropriately.

How to use

Enter the password. Choose the cost factor (log2 of the iteration count). The output is a PHC-format string starting with $2a$ or $2b$ that can be stored directly in a database column.

Cost 10 is the historical default. Modern recommendations: cost 12 or higher. Each increment doubles the work.

FAQ

What cost factor should I use?

Cost 12 in 2023 is a reasonable minimum. Some systems use cost 10 for compatibility. Higher is better if login latency allows.

Why is there a 72-byte limit?

bcrypt truncates password input to 72 bytes. Longer passwords are silently truncated, which is a common source of security issues. Use Argon2 or scrypt if you need unlimited length.

What about bcrypt variants ($2a$, $2b$, $2y$)?

These are minor version differences. This tool outputs the $2b$ variant, which is the current recommendation and fixes a wraparound bug in the original.

Is this done locally?

Yes. hash-wasm runs bcrypt in your browser. Nothing is uploaded.

Loads a test value into the form
Password
Bcrypt hash