Hash Generator (MD5, SHA-256)→Specialized Version
#️⃣

Bcrypt Hash Generator

Generate bcrypt password hashes

This generates PBKDF2-SHA256, not bcrypt. bcrypt needs a native library and cannot run in a browser. PBKDF2 is a real password KDF that Web Crypto implements, and OWASP accepts it at 600,000 iterations for SHA-256. The code samples below show the bcrypt and Argon2 equivalents for your server.

Never paste a password you actually use into any online tool, including this one.

Bcrypt Hash Generator

Generate bcrypt hashes for secure password storage. Bcrypt is specifically designed for password hashing, with built-in salt and configurable work factor to resist brute-force attacks.

Why Bcrypt for Passwords

FeatureBcryptSHA-256
PurposePasswordsGeneral hashing
Built-in saltYesNo
Adjustable slownessYesNo
GPU resistanceGoodPoor
Industry standardYesNo (for passwords)

Bcrypt Hash Format

`` $2b$12$LQv3c1yqBWVHxkd0LHAkCOYz6TtxMQJqhN8/X4beUYqL1qXWvEwZW │ │ │ │ │ │ │ │ └─ Salt (22 chars) └─ Hash (31 chars) │ │ └─ Cost factor (2^12 = 4096 rounds) │ └─ Version (2b) └─ Algorithm identifier `

Bcrypt Implementation

`javascript // Node.js with bcrypt const bcrypt = require('bcrypt');

// Hash a password async function hashPassword(password) { const saltRounds = 12; return await bcrypt.hash(password, saltRounds); }

// Verify a password async function verifyPassword(password, hash) { return await bcrypt.compare(password, hash); }

// Usage const hash = await hashPassword('mySecretPassword'); // "$2b$12$LQv3c1yqBWVHxkd0LHAkCOYz6TtxMQJqhN8/X4beUYqL1qXWvEwZW"

const isValid = await verifyPassword('mySecretPassword', hash); // true `

Cost Factor (Salt Rounds)

RoundsTime (~)Recommendation
10~100msDevelopment minimum
11~200msLight usage
12~400msRecommended default
13~800msHigh security
14~1.6sVery high security

Bcrypt Best Practices

1. Use cost factor 12+ for production 2. Never store plain passwords - always hash 3. Don't use pepper with bcrypt (controversial) 4. Increase cost factor as hardware improves 5. Use constant-time comparison (bcrypt.compare does this)

Bcrypt Limitations

LimitationDetail
Max password length72 bytes
No keyed hashingCan't use secret key
Single-threadedCan't parallelize
Consider Argon2 for new projects (memory-hard, more modern).

The Avalanche Effect

A one-character change produces a completely different digest — not a similar one. That property is what makes a hash useful as a fingerprint:

InputMD5CRC32
hello5d41402abc4b2a76b9719d911017c5923610a686
hello.d94c10e437d18531e122ed0b45badd2a0a39d4f1
Hello8b1a9953c4611296a827abf8c47804d7f7d18982
hello and Hello differ by one bit of one byte, and share no part of their output. RIPEMD-160 of hello is 108f07b8382412612c048d07d13f814118445acd, and of Hello is d44426aca8ae0a69cdbc4021c64fa5ad68ca32fe` — same story.

Digest Length and Collision Resistance

AlgorithmOutputBirthday boundStatus
CRC3232 bits~77,000 valuesChecksum only
MD5128 bits2⁶⁴ in theoryBroken — collisions in seconds
SHA-1160 bits2⁸⁰ in theoryBroken — SHAttered, 2017
RIPEMD-160160 bits2⁸⁰No practical attack
SHA-256256 bits2¹²⁸Current standard
SHA-512512 bits2²⁵⁶Standard, faster on 64-bit
The birthday bound is where a 50% chance of *some* collision appears among random inputs. MD5 and SHA-1 fall far short of theirs because both have practical collision attacks — you can construct two different files with the same digest, which is precisely what a signature must prevent.

Never Hash a Password With These

A general-purpose hash is designed to be fast, which is exactly wrong for passwords: speed helps the attacker. Use a deliberately slow KDF — bcrypt, scrypt or Argon2id — with a per-password salt. A GPU tries billions of SHA-256 guesses a second and a few thousand bcrypt guesses a second, and that gap is the entire defence.

Frequently Asked Questions

What cost factor should I use for bcrypt?

Use cost factor 12 as a baseline for production. The cost should make hashing take 250-500ms on your server. Increase the cost factor as hardware improves. Test on your production hardware: if 12 takes <100ms, increase to 13 or 14. Never go below 10. Balance security (higher is better) against user experience (login latency).

Why is bcrypt better than SHA-256 for passwords?

Bcrypt is designed specifically for passwords with three key features: 1) Built-in salt prevents rainbow table attacks, 2) Configurable cost factor makes it intentionally slow, resistant to brute force, 3) GPU-resistant design. SHA-256 is too fast (billions/second on GPUs) and lacks built-in salt. Always use bcrypt, argon2, or scrypt for passwords.

What is bcrypt's 72-byte password limit?

Bcrypt only processes the first 72 bytes of a password. Longer passwords are truncated. This is rarely an issue since 72 characters is very long for a password. If you need longer passwords, pre-hash with SHA-256 before bcrypt (controversial) or use Argon2 which has no such limit.

Related Tools

Explore other tools you might find useful:

More Hash Generator (MD5, SHA-256) tools

You might also need