Generate Bcrypt Hash
Compare Hash
What Is Bcrypt, and Why Is It Used for Password Storage?
Bcrypt is a hash function designed specifically for storing passwords. Unlike general-purpose hash functions such as MD5 or SHA-256, bcrypt is deliberately slow, and that slowness can be tuned with a "round" (cost factor) parameter — as the round count increases, the computation time grows exponentially (by a factor of 2^rounds). This design aims to make brute-force attacks, where an attacker tries millions of candidate passwords within seconds, practically infeasible.
Salt is included automatically: bcrypt automatically adds a random "salt" to every hash and embeds it inside the generated hash string itself (in the form $2a$10$saltAndHashValue…). This means the same password produces a different hash every time, which renders precomputed "rainbow table" attacks useless — and you don't need to store the salt separately for comparison either, the compare function extracts it from the hash itself.
This tool hashes or compares the text you enter entirely in your browser using the bcryptjs library — no data is ever sent to a server. In a real application, password hashing should be performed server-side; this tool is intended only for testing, learning, and quick verification.
Try This Next
Finished here? These might be your next step.
Frequently Asked Questions
$2a$10$…: it packs the algorithm version, the round count, the salt, and the actual digest into a single string.localStorage; everything is lost when you refresh the page.Last updated: