ManyHand logoManyHand ← All tools

Password Hash Generator

Plain text to a bcrypt or PBKDF2 password hash — computed on your device.

Algorithm
About this tool

Free online password hash generator

The ManyHand Password Hash Generator turns a plain-text password into a hash you can store in a database, seed file or config — and checks a password against a hash you already have. It supports bcrypt (cost 4–15, with the $2b$, $2y$ or $2a$ marker) and PBKDF2-SHA256 in the format Django uses. Everything runs in your browser: bcrypt in a background worker so the page stays responsive, and PBKDF2 with the built-in Web Crypto API. Your password is never uploaded.

Unlike a plain SHA-256 hash, a password hash is deliberately slow and salted, so a leaked database can't be reversed with lookup tables or brute force at billions of guesses a second.

Frequently asked questions
Is my password private?

Yes. Hashing happens locally in your browser; nothing is sent anywhere.

Why is the hash different every time?

Each hash gets a fresh random salt, stored inside the hash itself. Every one of them verifies against the same password — try it on the Verify tab.

Which bcrypt cost should I pick?

10–12 is typical. Each step doubles the work, for your server on every login and for an attacker on every guess.

What's the difference between $2a$, $2b$ and $2y$?

They label the same algorithm. $2b$ is the current standard, $2y$ is what PHP's password_hash() writes, and $2a$ is the older marker. Most libraries accept all three.

Why does bcrypt stop at 72 bytes?

bcrypt only reads the first 72 bytes of a password, so anything after that is ignored. The tool warns you when a password is longer.

More free tools: Password Generator · Hash Generator · JWT Decoder · All tools