How Bcrypt Hashing Works Securely
Bcrypt is a battle-tested password hashing function based on the Blowfish cipher. It incorporates a randomly generated "salt" into every hash to natively protect against rainbow table attacks.
Anatomy of a Bcrypt Signature
A standard bcrypt hash (e.g., $2a$10$vI8aWB...) breaks down into several parts:
- $2a$ / $2b$: The algorithm version identifier.
- 10$: The Work Factor (aka cost or rounds). Defined as 210 iterations.
- Remaining Base64 String: The 22-character Salt combined directly with the finalized 31-character checksum.
Fully Offline Sandbox
Never use an online generator that logs your master passwords! This tool utilizes bcryptjs directly within your browser's executing JavaScript bounds. Nothing is transmitted externally, completely preserving your cryptographic integrity.
