Reading a bcrypt hash
$2a$10$N9qo8uLOickgx2ZMRZoMye...
$2a$— the bcrypt version ($2a$, $2b$ and $2y$ are compatible)10— the cost factor: each +1 doubles the work- Next 22 characters — the salt; the rest is the hash
Choosing a cost factor
Cost 10–12 is a good default for web applications: hashing takes a fraction of a second for your server but makes brute-force attacks expensive. Higher values are slower in this tool too, because hashing runs in your browser.
Verifying
Paste a hash to check whether a password matches it. bcrypt hashes cannot be reversed — verification works by hashing the password again with the same salt.
Need a fast checksum instead? Use the MD5 & SHA Hash Generator (not for passwords).
Frequently asked questions
Why is the hash different every time?
bcrypt uses a new random salt for every hash. All of them verify the same password.
Can bcrypt be decrypted?
No. It is a one-way hash; you can only check whether a password matches.
Does PHP accept these hashes?
Yes, password_verify() accepts $2a$, $2b$ and $2y$ bcrypt hashes.

