We use cookies.This website uses essential cookies to operate core features. With your consent, we also use analytics cookies to understand traffic and improve the service. For more details, see our .
Was this tool helpful to use?
Your feedback helps us make it better
Generate PHP password_hash values online. Supports BCrypt, Argon2I, and Argon2ID algorithms for secure password storage.
The password is sent through this site’s server to a PHP cloud function. Cloud infrastructure logging and retention are unverified. Do not enter a real account password. Bcrypt is limited to 72 UTF-8 bytes.
Overview
Understand what the tool solves, how it works, and the boundaries of its data.
This page generates a bcrypt password hash for a test value. A password hash is a one-way representation used by an application to check a later login attempt; it is not encrypted text that can be decrypted to recover the password. PHP's password_hash() creates the hash, and the returned string contains the information PHP needs for later verification, including the algorithm, cost and salt. The salt means that hashing the same input again can produce a different string.
For the bcrypt option, the form accepts a cost from 4 to 15 and starts at 10. A higher cost makes each hash operation more computationally expensive. The generator accepts UTF-8 text up to 72 bytes in bcrypt mode, and the input is sent to a server for processing. The result is a hash string you can copy into a development fixture or use to understand PHP's hash format.
A bcrypt result commonly begins with a marker such as $2y$. The next part records the cost; the remainder includes the salt and derived hash data. Keep the entire returned string intact because PHP needs it to verify a candidate password. Do not treat the visible marker as a secret or as proof that an application is configured securely.
To check a login in your own PHP application, retrieve the previously stored hash and call password_verify($candidate, $storedHash). Do not hash the candidate again and compare the two full strings: the salt makes separate hash operations differ. This page generates a hash; it does not verify a password against a hash you provide.
password_hash(); documents one-way hashing, bcrypt input and cost behavior, salts, and information carried in the result; checked 2026-10-02. Read the PHP password_hash manualpassword_verify(); documents verification of a candidate against a stored hash; checked 2026-10-02. Read the PHP password_verify manualGuide
Follow the workflow and verify inputs and outputs with practical examples.
Type a made-up password for a fixture or code experiment. The input is sent to a server to be processed, so do not use a real account password or a production secret.
Select the bcrypt algorithm. Its cost field accepts an integer from 4 through 15 and begins at 10. Leave the value at its starting setting for a simple format example, or choose a value to test behavior in a non-production exercise.
Run the generator and copy the full result, including its prefix. Store it only in a safe test fixture. When you test a login flow, pass the candidate and stored string to password_verify() in your own PHP code.
Use cases
See how the tool fits into real work and everyday tasks.
A PHP developer can create a hash from a throwaway value, place the complete string in a local test record, and exercise the application's password verification branch with both matching and non-matching candidates.
A learner reviewing password storage can inspect how a bcrypt result carries its parameters, then compare that structure with the PHP manual. The example is useful for learning and test data, not for configuring a live account system.
Q&A
Find concise answers to common questions and confusing cases.
PHP generates a salt for a new hash, so separate calls can return different strings for identical input. Verify a candidate against the stored string with password_verify() instead of comparing independently generated hashes.
It changes the computational work used to create and verify the hash. The available form setting is an integer from 4 to 15; the value that makes sense for a real application must be benchmarked in that application's own environment.
This generator rejects bcrypt input above 72 UTF-8 bytes. PHP documents that bcrypt truncates longer input, which could make distinct long inputs behave alike. Count encoded bytes, not visible characters: some Unicode characters take multiple UTF-8 bytes.
No. It generates a new hash from an input value. In a PHP application, use password_verify($candidate, $storedHash) with the candidate and the complete previously stored hash.
Notes
Review scope, result limitations, and important precautions before use.
The password value is sent through the service for processing. Infrastructure logging and retention have not been verified, so use only synthetic test strings; do not enter a real account password, API key, or production data. A generated hash does not establish that a password is strong or that an application's storage and login design is secure.
Use PHP's password functions in the application environment for real account creation and login. Benchmark the cost on the hardware that will run the application and follow current security guidance. This page's cost range and output are for testing and inspection, not a production security recommendation.
For bcrypt, the 72-byte boundary applies to UTF-8 bytes rather than the number of displayed characters. Choose another approach in your application if your password policy requires longer inputs, and make sure the same policy is applied consistently during enrollment and verification.
Related
Discover related tools, collections, and available API capabilities.