Password Hasher
BetaHash a password with bcrypt or Argon2id, or check a password against a stored hash. Choose the cost or memory settings. Runs in your browser.
- Free, no sign-up
- Updated
- Reviewed by Olgun Ozoktas
Runs in your browser. Nothing is uploaded.
Encoded hash
Result
No result yet
Enter the password and the stored hash, then verify.
For storing passwords in your own app. For file checksums use the MD5 & SHA hash tools.
How to Hash or Verify a Password
-
Pick the algorithm
On the Hash tab choose bcrypt or Argon2id. Argon2id is the first choice in the OWASP Password Storage Cheat Sheet; bcrypt is common in existing systems and frameworks. -
Enter the password and settings
Type the password. For bcrypt set the cost factor from 4 to 14 (default 12). For Argon2id set memory in MiB, iterations and parallelism (defaults 19 MiB, 2, 1). -
Hash it
Press Hash password. The work runs in a background thread, so the page stays responsive, and the time it took is shown under the result. Copy the encoded hash; the salt and settings are inside it. -
Verify a stored hash
On the Verify tab paste the password and the stored hash. The tool detects bcrypt or Argon2 and its settings, and tells you Match or No match.
Common Use Cases
Seed a test or admin user
Debug a failing login
Choose a cost setting
Check a hash from another language
Why Hash Passwords with bcrypt or Argon2id?
The Password Hasher creates and checks bcrypt and Argon2id password hashes. On the Hash tab you choose the algorithm and its settings: a bcrypt cost factor from 4 to 14, or Argon2id memory (1 to 256 MiB), iterations (1 to 10) and parallelism (1 to 4). Every hash gets a fresh random 16-byte salt, and the output is the standard encoded string, such as $2b$12$... or $argon2id$v=19$m=19456,t=2,p=1$..., that server libraries store and read. The work runs in a background thread in your browser, so a slow setting does not freeze the page, and the password is not uploaded.
On the Verify tab you paste a password and a stored hash. The tool recognises bcrypt ($2a$, $2b$ and $2y$) and Argon2 (argon2id, argon2i and argon2d) strings, shows the settings they were made with, and reports Match or No match. Anything else, such as an MD5 or SHA hex digest, is refused with a clear message.
Need a password to hash first? Make one with the Password Generator, check it with the Password Strength Checker, and see whether it appeared in a known breach with the Password Breach Checker. For signing messages, use the HMAC Generator; for checksums, the MD5 Hash Generator.
How it compares
In an application you would hash passwords with your framework's library, such as PHP's password_hash, a bcrypt or argon2 package for Node or Python, or Go's x/crypto. Those produce the same encoded formats as this page, so a hash made here verifies there and the other way round. This page is useful when you do not want to write a script: to make a one-off hash for a seed file, to check a value from a database, or to feel the cost of a setting.
Compared with a fast hash such as MD5 or SHA-256, bcrypt and Argon2id are slow by design and salted by default, which is what password storage needs. Argon2id is also memory-hard, which makes guessing on graphics cards more expensive. bcrypt has a 72-byte input limit that Argon2id does not have.
Tips for Password Hashing
- Store the whole encoded string. The algorithm, the settings and the random salt are all part of it, and a verifier needs every part.
- bcrypt ignores every byte after the first 72. For long passphrases, use Argon2id.
- The same password gives a different hash every time because each hash gets a new random 16-byte salt. That is expected; use Verify to compare.
- Times here are measured in your browser. Your server can be faster or slower, so measure there before you settle on a cost.
- Use a slow password hash only for passwords. For file checksums or message signing, use SHA-256 or HMAC instead.