Password Hash Generator
Plain text to a bcrypt or PBKDF2 password hash — computed on your device.
pbkdf2_sha256$iterations$salt$hash format. OWASP recommends at least 600,000.
Free online password hash generator
The ManyHand Password Hash Generator turns a plain-text password into a hash you can store in a database, seed file or config — and checks a password against a hash you already have. It supports bcrypt (cost 4–15, with the $2b$, $2y$ or $2a$ marker) and PBKDF2-SHA256 in the format Django uses. Everything runs in your browser: bcrypt in a background worker so the page stays responsive, and PBKDF2 with the built-in Web Crypto API. Your password is never uploaded.
Unlike a plain SHA-256 hash, a password hash is deliberately slow and salted, so a leaked database can't be reversed with lookup tables or brute force at billions of guesses a second.
Is my password private?
Yes. Hashing happens locally in your browser; nothing is sent anywhere.
Why is the hash different every time?
Each hash gets a fresh random salt, stored inside the hash itself. Every one of them verifies against the same password — try it on the Verify tab.
Which bcrypt cost should I pick?
10–12 is typical. Each step doubles the work, for your server on every login and for an attacker on every guess.
What's the difference between $2a$, $2b$ and $2y$?
They label the same algorithm. $2b$ is the current standard, $2y$ is what PHP's password_hash() writes, and $2a$ is the older marker. Most libraries accept all three.
Why does bcrypt stop at 72 bytes?
bcrypt only reads the first 72 bytes of a password, so anything after that is ignored. The tool warns you when a password is longer.
More free tools: Password Generator · Hash Generator · JWT Decoder · All tools