bcrypt / MD5 / SHA-256 Generator
Generate and verify bcrypt password hashes and calculate MD5 and SHA-256 digests locally.
Input
Private by design: your input never leaves your device. Production passwords should preferably be handled server-side.
MD5 is collision-broken. SHA-256 is a fast digest and alone is not suitable for password storage. OWASP prefers Argon2id for new systems.
Result
Good to know
Good to know
The bcrypt/MD5/SHA-256 generator computes hashes directly in your browser with three algorithms. bcrypt uses a random salt and the $2b$ prefix and blocks new passwords over 72 UTF-8 bytes; a digest mode additionally compares the result against an expected value.
Typical searches include bcrypt generator, SHA-256 hash generator, and create password hash. Hex and base64 output represent bytes, not text. Important: MD5 is collision-broken, SHA-256 is a fast digest and alone unsuitable for password storage — OWASP recommends Argon2id for new systems, and production passwords should preferably be processed server-side.
Typical use cases
Hash a test password for a local development database
Generate a bcrypt hash for a test password to check local authentication logic without using production secrets.
Verify file integrity against an expected digest with SHA-256
Compute the SHA-256 digest of a file and compare it in digest-verify mode against the expected value, to rule out tampering.
Tips for better results
bcrypt for passwords, SHA-256 for integrity
Use bcrypt for password hashing and SHA-256 more for checksums and fingerprints — SHA-256 alone, being a fast digest, is not suitable for passwords.
Watch bcrypt's 72-byte limit
bcrypt blocks new passwords over 72 UTF-8 bytes — this can become relevant for very long passphrases.
How it works
How it works
Step by step
Features
Features
Three algorithms
bcrypt with a random salt, MD5 checksums, and SHA-256 hashes.
Digest-verify mode
Compare a computed digest directly against an expected value.
Local computation
Your inputs never leave your device; hash computation runs entirely in the browser.
Frequently asked questions
Frequently asked questions
Is SHA-256 suitable for passwords?
Not alone — SHA-256 is a fast digest without a built-in salt or work factor. For new systems, OWASP prefers Argon2id; bcrypt is available here as an alternative.
Are my inputs uploaded?
No. Computation runs entirely locally in the browser.
More tools
More tools
UUID / GUID Generator
Generate UUIDs and GUIDs locally in the browser, export batches, and use v4 or v7.
Base64 Encoder
Encode text or local files to Base64, Base64URL, MIME Base64, or data URLs directly in the browser.
Base64 Decoder
Decode Base64, Base64URL, MIME Base64, or data URLs to bytes directly in the browser.
JWT Decoder
Decode JWTs locally, inspect claims, and optionally verify HMAC signatures in the browser.