Hash passwords with bcrypt in your browser. Adjust rounds to match your app's cost factor. Bcrypt input never leaves your device.
Bcrypt is a password hashing algorithm designed to be slow and resistant to GPU-accelerated brute-force attacks. It embeds the work factor (cost) in the hash output, making it easy to increase difficulty over time.
Higher bcrypt cost means slower hashes and stronger brute-force resistance. A cost of 12 is a common production default. Use values that match your app's performance requirements.
Bcrypt Hash Generator exists to produce a bcrypt hash with a cost factor for a development test, without sending the password to a server. It is not a second copy of the tool homepage. The homepage introduces the whole product. This page stays on one job so a search for that job lands on instructions you can follow without hunting through other tabs. Read the result on this page against the input you actually used. A screenshot without the input is not evidence. If the result surprises you, change one thing and run it again before you change your VPN, browser, or server config.
Work through Bcrypt Hash Generator in order. 1. Set the cost to the cost your application uses. 2. Hash the password locally. 3. Copy the modular crypt string, including the prefix and cost. 4. Do not commit a real user's password into a ticket beside the hash. Write down the input and the output together. When you ask someone for help, send both. Repeat the same input once. A stable tool returns the same answer. If it does not, the input changed or the page is talking to a different network path than you think.
Bcrypt hashes are not portable across every wrapper's minor dialect. Test against your verifier. A low cost is fine for a unit test and wrong for production. This page does not log the user in. Treat the output as a measurement, then decide. RookVPN does not log the contents of a client-side tool, and a measurement is not a promise that every other app on the device behaves the same way. Compare a second path when the decision matters: a terminal command, another browser, or the matching guide linked below.
Example: your app uses cost 12. You generate a hash here at cost 12 and your test verifier accepts it. A hash you made at cost 4 will also verify and will be the one an attacker wants. Match production cost. The string starts with $2 and embeds the cost. Store that whole string.
After you finish Bcrypt Hash Generator, open RookPass if you do not have a password worth hashing yet if the next question is different from the one this page answers. Stay here if you are still on the same job. Extra pages help only when they answer a new question, such as a different algorithm, a different leak channel, or a different file type. The documentation link on this page is the long form of the same workflow, including the checks that do not fit in the tool UI.
No. Bcrypt is one-way. You can only verify a candidate password against a hash — you cannot reverse it to obtain the original password.
A cost factor of 10–12 is typical for web applications. Higher values increase security but also increase CPU time per hash — test your server throughput before increasing cost in production.
Yes. Bcrypt is widely recommended for password hashing. It automatically includes a random salt and is intentionally slow, making offline brute-force attacks expensive.
The cost is the defense. SHA-256 is the fast one you should not use for passwords.
The work factor embedded in the hash. Higher is slower.
No.