---
title: "Password Hasher"
description: "Hash a password with bcrypt or Argon2id, or check a password against a stored hash. Choose the cost or memory settings. Runs in your browser."
url: https://findutils.com/security/password-hasher/
category: security
---

# Password Hasher

Hash a password with bcrypt or Argon2id, or check a password against a stored hash. Choose the cost or memory settings. Runs in your browser.

**Use this tool:** [Password Hasher](https://findutils.com/security/password-hasher/)

## Programmatic access

- Browser-only: this tool works on a file, the DOM, or a browser API and has no REST or MCP id.

## Why Hash Passwords with bcrypt or Argon2id?

A password database should never hold the passwords themselves. bcrypt and Argon2id are built to be slow on purpose and add a random salt to every hash, so a leaked table costs an attacker far more time per guess than a fast hash such as MD5 or SHA-256. This tool makes those hashes and checks them, so you can create a test user, check a stored value from your database, or see what a cost setting feels like before you pick it.

## Tips for Password Hashing

- Store the whole encoded string. The algorithm, the settings and the random salt are all part of it, and a verifier needs every part.
- bcrypt ignores every byte after the first 72. For long passphrases, use Argon2id.
- The same password gives a different hash every time because each hash gets a new random 16-byte salt. That is expected; use Verify to compare.
- Times here are measured in your browser. Your server can be faster or slower, so measure there before you settle on a cost.
- Use a slow password hash only for passwords. For file checksums or message signing, use SHA-256 or HMAC instead.

## Frequently Asked Questions

### What does the Password Hasher do?

It hashes a password with bcrypt or Argon2id and gives you the encoded hash to store, or it checks a password against a stored bcrypt or Argon2 hash and tells you Match or No match. It runs in your browser and the password is not uploaded.

### Should I use bcrypt or Argon2id?

For a new system, Argon2id. The OWASP Password Storage Cheat Sheet recommends Argon2id with at least 19 MiB of memory, 2 iterations and parallelism 1, which are this tool's defaults. It lists bcrypt with a cost of 10 or more for legacy systems where Argon2id is not available.

### What bcrypt cost factor should I choose?

The default here is 12. Each step up doubles the work, so cost 13 takes about twice as long as 12. Pick the highest cost your login server can handle at its peak load, and do not go below 10. Measure on your own server, because this page measures your browser.

### Why does the same password give a different hash each time?

Each hash gets a new random 16-byte salt, and the salt is written into the encoded hash. Two hashes of the same password therefore look different, and both verify. That stops an attacker from spotting users who share a password.

### Why does bcrypt refuse my long password?

bcrypt only reads the first 72 bytes of a password and silently ignores the rest. Rather than create a hash that ignores part of what you typed, this tool refuses passwords over 72 bytes (letters outside basic Latin take 2 to 4 bytes each). Use Argon2id for longer passwords.

### Can I verify a hash made by PHP, Node or Python?

Yes. The verifier reads the standard encoded formats: bcrypt strings starting with $2a$, $2b$ or $2y$ (PHP's password_hash writes $2y$; the old $2x$ marker from a buggy implementation is not accepted, because it does not match $2b$ for non-ASCII passwords), and Argon2 strings starting with $argon2id$, $argon2i$ or $argon2d$. New bcrypt hashes are written as $2b$.

### Why is there no API for this tool?

It is browser-only on purpose. bcrypt and Argon2id are deliberately slow and memory-hungry, which is the point of a password hash, and that work belongs on your device or your own server rather than a shared API. Many other FindUtils tools do have an API.

### Is my password sent anywhere?

No. Hashing and verifying run in a background thread in your browser, and the password is not uploaded or saved to browser storage. Even so, for a real production password, the safest place to hash it is your own server.

### Why does the tool say my hash is not a bcrypt or Argon2 hash?

The stored value does not have the bcrypt or Argon2 format. A 32-character hex string is usually MD5, and 64 hex characters are usually SHA-256. Those are fast checksums, not password hashes, and this tool does not verify them. Use the MD5 & SHA hash tools for those.

### Can I use this for file checksums?

No. bcrypt and Argon2id are for storing passwords. For file checksums use the MD5 & SHA hash tools or the File Hash Calculator, which are fast and give the same digest every time.

## Related Tools

- [Password Generator](https://findutils.com/security/password-generator/)
- [Password Strength Checker](https://findutils.com/security/password-strength-checker/)
- [Password Breach Checker](https://findutils.com/security/password-breach-checker/)
- [MD5 Hash Generator](https://findutils.com/security/md5-hash-generator/)
- [HMAC Generator](https://findutils.com/security/hmac-generator/)
- [Random Key Generator](https://findutils.com/security/random-key-generator/)
