gizmobench
BrowseDaily

Bcrypt Password Checker

Verify a known candidate password against a stored bcrypt hash. This page opens with Verify first: paste the password and full hash, then run the check. The salt and cost are read from the hash, and the result is match or mismatch. Both inputs stay in this tab.

verify

paste a hash, or generate one

0 characters, 0 of 72 bytes

reads$2a$, $2b$ and $2y$ hashes; Generate is set to $2a$

costtaken from the hash, 4 to 16 here

no result yet

elapsednot run yet

each step in cost doubles the rounds: 4 is 16, 10 is 1,024, 14 is 16,384, 16 is 65,536

generate

cost 10

0 characters, 0 of 72 bytes

10 = 2^10 = 1,024 rounds

salt16 random bytes, new each time

the hash appears here

elapsednot run yet

Cost
10, 1,024 rounds
Password
0 of 72 bytes
Verify
not run
Elapsed
not run

  • Published vector, password abc$2a$06$If6bvum7DFjUnE9p2uDeDu0YHzrHM6tf.iqN8.yx.jNN1ILEf7h0i
    press Run to check it in this browser
  • 72 a's, then 72 a's plus é73 characters, 74 bytes in UTF-8, one salt for both
    press Run to hash both here
  • Cancel at cost 14an example password, cancelled 200 ms in
    press Run to start one and cancel it

Accuracy. Generate computes each hash on this device with hash-wasm 4.12.0 in a worker, using a new 16-byte salt from crypto.getRandomValues, and writes your selected $2a$, $2b$ or $2y$ prefix; nothing typed here is sent or stored. bcrypt reads at most 72 bytes of UTF-8, so a longer password is flagged and bytes past the 72nd do not change the hash. Cost runs from 4 to 14 when generating and up to 16 when verifying, each step doubling the rounds; the elapsed time is this browser's and says nothing about password strength.

Common questions

How do I verify a password against a bcrypt hash?
Choose Verify first, paste the candidate password and the complete 60-character $2a$, $2b$ or $2y$ hash, then press Verify. Cost and salt come from that stored hash, so you do not enter a separate salt. A match is true and a mismatch is false. Editing either input clears the old result, and Cancel stops the worker. This checks one known candidate; it does not recover a password.
Why does bcrypt ignore everything after 72 bytes?
bcrypt's key setup cycles the password through Blowfish's 18 subkeys of 4 bytes each, 72 bytes in all, so nothing after the 72nd byte of the UTF-8 text reaches the hash. The letter a is one byte, é is two, € is three and most emoji are four, so the limit can arrive well before 72 characters. This page counts bytes as you type and flags a longer password. The 72-byte case under the tool hashes 72 a's and 72 a's plus é with one salt and gets the same hash for both.
What is the difference between $2a$, $2b$ and $2y$?
They mark revisions of bcrypt. This page can generate any of these three output prefixes and verify them. For the NUL-free UTF-8 passwords prepared here, limited to the first 72 bytes, the supported revisions share the same salt/checksum computation. The engine computes $2a$ and the chosen compatible prefix is written on that result. The worker refuses a non-UTF-8 0xFF safety-case byte for alternate prefixes. This is not a promise that arbitrary historical binary-password records are interchangeable. $2x$ hashes, which identify the old buggy computation, are refused.
Why does verify stop at cost 16?
Every step doubles the work: cost 17 is 131,072 rounds, 8 times cost 14, and cost 20 is 64 times, about a minute at the speed above. This page bounds a check at cost 16: it verifies hashes from cost 4 to 16 and names the cost of any hash above that instead of running it.
Can this decrypt or reverse a bcrypt hash?
No. bcrypt is one-way. Verify answers one question: does the password you typed match this hash, true or false.

Generate computes each hash on this device with hash-wasm 4.12.0 in a worker, using a new 16-byte salt from crypto.getRandomValues, and writes your selected $2a$, $2b$ or $2y$ prefix; nothing typed here is sent or stored. bcrypt reads at most 72 bytes of UTF-8, so a longer password is flagged and bytes past the 72nd do not change the hash. Cost runs from 4 to 14 when generating and up to 16 when verifying, each step doubling the rounds; the elapsed time is this browser's and says nothing about password strength.