Skip to content

Security

Password Hasher

Password Hasher

Beta

Hash a password with bcrypt or Argon2id, or check a password against a stored hash. Choose the cost or memory settings. Runs in your browser.

  • Free, no sign-up
  • Updated
  • Reviewed by Olgun Ozoktas

Runs in your browser. Nothing is uploaded.

Algorithm

bcrypt reads at most 72 bytes of a password. This one is 0 bytes.

12
4 · faster14 · slower

Default is 12. Each step up doubles the time it takes to hash.

Encoded hash

Your hash appears here.

For storing passwords in your own app. For file checksums use the MD5 & SHA hash tools.

How to Hash or Verify a Password

  1. Pick the algorithm

    On the Hash tab choose bcrypt or Argon2id. Argon2id is the first choice in the OWASP Password Storage Cheat Sheet; bcrypt is common in existing systems and frameworks.
  2. Enter the password and settings

    Type the password. For bcrypt set the cost factor from 4 to 14 (default 12). For Argon2id set memory in MiB, iterations and parallelism (defaults 19 MiB, 2, 1).
  3. Hash it

    Press Hash password. The work runs in a background thread, so the page stays responsive, and the time it took is shown under the result. Copy the encoded hash; the salt and settings are inside it.
  4. Verify a stored hash

    On the Verify tab paste the password and the stored hash. The tool detects bcrypt or Argon2 and its settings, and tells you Match or No match.

Common Use Cases

Seed a test or admin user

Create a bcrypt or Argon2id hash to put in a seed file, fixture or SQL insert, so a development account has a known password.

Debug a failing login

Paste the hash from your users table and the password you expect. A No match result tells you the stored value, not your login code, is the problem.

Choose a cost setting

Try different bcrypt costs or Argon2id memory settings and compare the time each one takes in your browser before you set it in your app.

Check a hash from another language

Hashes from PHP password_hash ($2y$), Node, Python and Go libraries use the same encoded formats, so you can check one made elsewhere.

Why Hash Passwords with bcrypt or Argon2id?

A password database should never hold the passwords themselves. bcrypt and Argon2id are built to be slow on purpose and add a random salt to every hash, so a leaked table costs an attacker far more time per guess than a fast hash such as MD5 or SHA-256. This tool makes those hashes and checks them, so you can create a test user, check a stored value from your database, or see what a cost setting feels like before you pick it.

The Password Hasher creates and checks bcrypt and Argon2id password hashes. On the Hash tab you choose the algorithm and its settings: a bcrypt cost factor from 4 to 14, or Argon2id memory (1 to 256 MiB), iterations (1 to 10) and parallelism (1 to 4). Every hash gets a fresh random 16-byte salt, and the output is the standard encoded string, such as $2b$12$... or $argon2id$v=19$m=19456,t=2,p=1$..., that server libraries store and read. The work runs in a background thread in your browser, so a slow setting does not freeze the page, and the password is not uploaded.

On the Verify tab you paste a password and a stored hash. The tool recognises bcrypt ($2a$, $2b$ and $2y$) and Argon2 (argon2id, argon2i and argon2d) strings, shows the settings they were made with, and reports Match or No match. Anything else, such as an MD5 or SHA hex digest, is refused with a clear message.

Need a password to hash first? Make one with the Password Generator, check it with the Password Strength Checker, and see whether it appeared in a known breach with the Password Breach Checker. For signing messages, use the HMAC Generator; for checksums, the MD5 Hash Generator.

How it compares

In an application you would hash passwords with your framework's library, such as PHP's password_hash, a bcrypt or argon2 package for Node or Python, or Go's x/crypto. Those produce the same encoded formats as this page, so a hash made here verifies there and the other way round. This page is useful when you do not want to write a script: to make a one-off hash for a seed file, to check a value from a database, or to feel the cost of a setting.

Compared with a fast hash such as MD5 or SHA-256, bcrypt and Argon2id are slow by design and salted by default, which is what password storage needs. Argon2id is also memory-hard, which makes guessing on graphics cards more expensive. bcrypt has a 72-byte input limit that Argon2id does not have.

Tips for Password Hashing

  • Store the whole encoded string. The algorithm, the settings and the random salt are all part of it, and a verifier needs every part.
  • bcrypt ignores every byte after the first 72. For long passphrases, use Argon2id.
  • The same password gives a different hash every time because each hash gets a new random 16-byte salt. That is expected; use Verify to compare.
  • Times here are measured in your browser. Your server can be faster or slower, so measure there before you settle on a cost.
  • Use a slow password hash only for passwords. For file checksums or message signing, use SHA-256 or HMAC instead.

Frequently Asked Questions

What does the Password Hasher do?

It hashes a password with bcrypt or Argon2id and gives you the encoded hash to store, or it checks a password against a stored bcrypt or Argon2 hash and tells you Match or No match. It runs in your browser and the password is not uploaded.

Should I use bcrypt or Argon2id?

For a new system, Argon2id. The OWASP Password Storage Cheat Sheet recommends Argon2id with at least 19 MiB of memory, 2 iterations and parallelism 1, which are this tool's defaults. It lists bcrypt with a cost of 10 or more for legacy systems where Argon2id is not available.

What bcrypt cost factor should I choose?

The default here is 12. Each step up doubles the work, so cost 13 takes about twice as long as 12. Pick the highest cost your login server can handle at its peak load, and do not go below 10. Measure on your own server, because this page measures your browser.

Why does the same password give a different hash each time?

Each hash gets a new random 16-byte salt, and the salt is written into the encoded hash. Two hashes of the same password therefore look different, and both verify. That stops an attacker from spotting users who share a password.

Why does bcrypt refuse my long password?

bcrypt only reads the first 72 bytes of a password and silently ignores the rest. Rather than create a hash that ignores part of what you typed, this tool refuses passwords over 72 bytes (letters outside basic Latin take 2 to 4 bytes each). Use Argon2id for longer passwords.

Can I verify a hash made by PHP, Node or Python?

Yes. The verifier reads the standard encoded formats: bcrypt strings starting with $2a$, $2b$ or $2y$ (PHP's password_hash writes $2y$; the old $2x$ marker from a buggy implementation is not accepted, because it does not match $2b$ for non-ASCII passwords), and Argon2 strings starting with $argon2id$, $argon2i$ or $argon2d$. New bcrypt hashes are written as $2b$.

Why is there no API for this tool?

It is browser-only on purpose. bcrypt and Argon2id are deliberately slow and memory-hungry, which is the point of a password hash, and that work belongs on your device or your own server rather than a shared API. Many other FindUtils tools do have an API.

Is my password sent anywhere?

No. Hashing and verifying run in a background thread in your browser, and the password is not uploaded or saved to browser storage. Even so, for a real production password, the safest place to hash it is your own server.

Why does the tool say my hash is not a bcrypt or Argon2 hash?

The stored value does not have the bcrypt or Argon2 format. A 32-character hex string is usually MD5, and 64 hex characters are usually SHA-256. Those are fast checksums, not password hashes, and this tool does not verify them. Use the MD5 & SHA hash tools for those.

Can I use this for file checksums?

No. bcrypt and Argon2id are for storing passwords. For file checksums use the MD5 & SHA hash tools or the File Hash Calculator, which are fast and give the same digest every time.

Rate This Tool

0/1000

Get Weekly Tools

Suggest a Tool