BCrypt Hash Checker | Verify Password Matches Hash Instantly
Check for free whether a password matches a BCrypt hash in seconds. Works the same way as PHP's password_verify(), making it ideal for debugging login issues. Supports both $2a$ and $2b$ hash formats.
| Hash | |
|---|---|
| Text |
Success
Failure
What Is BCrypt Verification?
This tool checks whether a plain-text password you enter and an existing BCrypt hash were generated from the same original string. It works on the same principle as PHP's password_verify() function, so it serves for confirming and debugging a login implementation.
A BCrypt hash carries its salt inside it, which is why generating one from the same password produces a different string every time. Plain string comparison therefore cannot verify a match: the salt has to be extracted with the dedicated algorithm before comparing, and this tool performs that step for you.
How to Use BCrypt Verification
- Enter the string Type the plain-text password you want to verify into the input box.
- Enter the hash Paste a BCrypt hash beginning with $2a$ or $2b$.
- Press the verify button The result — match or no match — appears instantly.
Tips for getting more out of it
- BCrypt embeds the salt in the hash, so even though the hash value differs each time, it will be judged as a match if it was generated from the same original input.
- This tool verifies using the same mechanism as PHP's
password_verify($password, $hash). - When comparing a hash retrieved from a database with an entered password, use a dedicated verification function rather than a plain string comparison (
==) to prevent timing attacks. - Hash values starting with
$2a$can also be verified as BCrypt.
When BCrypt Verification Comes in Handy
Debugging a login flow
Check directly whether a hash stored in the database matches the password you expect, without going through your application code.
Confirming behaviour after a password reset
Test whether a hash generated from a new password matches the plain text you intended.
Verifying hashes during a migration
Confirm in advance that BCrypt hashes carried over from another system will still work.
BCrypt Glossary
- Salt
- A random string added when the hash is generated. It is what makes the same password produce a different hash every time.
- password_verify()
- PHP's standard function for comparing a plain-text password against a hash safely. It handles extracting the salt automatically, internally.
- Timing Attack
- An attack that infers secret information from tiny differences in processing time. Using a dedicated function that compares in constant time prevents it.
- $2a$ / $2b$
- The prefixes indicating the version of a BCrypt hash. $2b$ is the version that fixed a bug in an older implementation and is the one recommended today.
FAQ
$2b$ is a bug-fixed version of the older implementation, and its use is currently recommended.
Side Note — Behind Authentication: What Those Few Hundred Milliseconds on Login Are
When you press the login button on a web service, part of those few hundred milliseconds before the result comes back is the time BCrypt spends computing the password hash. That delay is intentional — done for security.
A Timing Attack is a type of side-channel attack where an attacker infers secret information by measuring subtle differences in processing time. When a password is verified with a plain string comparison (==), the comparison time varies slightly depending on where the characters stop matching. BCrypt's verification function is designed to run in constant time, making it safe against this attack.
In real web applications, it is recommended to return a response in the same amount of time whether or not the user exists, as if the user exists but the password is wrong. If an attacker can distinguish "user does not exist" from "wrong password," it gives them a hint to identify valid usernames.