Data Hashing Utility
Compute MD5 and SHA digests plus Bcrypt password hashes right in your browser — nothing you type is ever uploaded.
Security notice: all computation happens locally in your browser
The text you type stays in this browser tab. It is never sent to a server and never logged.
Digests update as you type, entirely inside your browser.
Digests (lowercase hexadecimal)
Bcrypt password hash
Bcrypt draws a fresh random salt every time, so the same text produces a different result on every run — exactly what password storage should do.
- Version
- —
- Cost
- —
- Random salt
- —
- Hash value
- —
Cost 10 means 2¹⁰ = 1,024 key expansions; it is deliberately slow to resist brute force.
💡 Crypto best practice: why is the Bcrypt hash different every time?
Because a brand new random salt is generated on every run. The salt is mixed into the computation, so the same password yields a completely different hash each time — two users with the same password never share a hash in the database. Verification re-runs the computation with the stored salt, which is why the salt must be kept alongside the hash.
Common mistake: why can you not store passwords with SHA-256?
SHA-256 is far too fast: modern GPUs compute billions of hashes per second, so an attacker can try dictionaries and variants offline at enormous speed. Bcrypt is deliberately slow (tunable through Cost), making every attempt expensive and defeating hardware-accelerated cracking.
Algorithm recommendation matrix
| Use case | First choice | Notes |
|---|---|---|
| Password storage | Bcrypt / Argon2 | Built for passwords: random salt, tunable cost, deliberately slow. |
| Digital signature / file checksum | SHA-256 / SHA-3 | Fast and collision resistant — verifies integrity, but not for passwords. |
| Legacy compatibility | MD5 | Fast and widely supported, but collisions are practical: never use it for security. |