Bcrypt is a slow, salted password-hashing algorithm — its cost factor controls how many rounds it repeats internally, making brute-force attempts deliberately expensive. Use Hash to generate a new hash for a password, or Verify to check a password against an existing hash.
Hashing runs entirely in your browser using the open-source bcryptjs library — the password and the resulting hash are never sent to a server.
Is my password sent anywhere?
No — hashing and verification run entirely in your browser. Neither the password nor the resulting hash is sent to a server.
What does the cost factor control?
How many times bcrypt repeats its internal hashing rounds — higher is slower to compute (and to brute-force) but takes longer to generate. 10-12 is a common default for production use.
Why doesn't hashing the same password twice give the same hash?
Bcrypt embeds a random salt in every hash it generates, so the same password produces a different hash each time — this is expected, and verification still works because the salt is stored inside the hash itself.