Htpasswd Generator
Creates .htpasswd lines with bcrypt, APR1-MD5, or SHA-1 hashes for Basic Auth.
Hash a password with bcrypt at the cost you choose, or check whether a password matches an existing bcrypt hash. Hashing runs in a background worker, so even cost 14 won't freeze the page.
A bcrypt hash looks like $2y$10$ followed by 53 characters:
2y is the version, 10 is the cost, and the next 22 characters are a random 128-bit salt.Hashing uses bcryptjs in a Web Worker in your browser.
correct horse battery staple at cost 10 gives a hash such as $2y$10$ + 53 characters. Your hash will differ each time because of the salt.$2y$ (PHP) and one with $2b$ (Node, Python) are the same algorithm. Changing the prefix is enough to move between them.| Prefix | Where you see it |
|---|---|
$2y$ | PHP password_hash(), Apache htpasswd -B, Laravel |
$2b$ | OpenBSD, Node bcrypt, Python bcrypt, current standard |
$2a$ | Older libraries, Spring Security |
Cost 10 is the common default, and 12 is a good choice for most servers today. Pick the highest cost that keeps a login at about a quarter of a second on your server.
Each hash gets a new random salt. That's intended: two users with the same password end up with different hashes. Both still verify.
No. Bcrypt is one-way. You can only check whether a guessed password produces the same hash, and the cost makes each guess slow.
No. Hashing and checking run in your browser, and nothing is stored.
Often used together with the Bcrypt Generator.
Creates .htpasswd lines with bcrypt, APR1-MD5, or SHA-1 hashes for Basic Auth.
Creates strong random passwords with a chosen length and character set.
Estimates how guessable a password is and explains what weakens it.