How does bcrypt password hashing work?
Bcrypt is a password-hashing function that combines a password with a random salt and repeats an expensive key setup according to a configurable cost. The resulting 60-character string stores the algorithm version, cost, salt, and hash so a later password can be checked without recovering the original.
This page uses bcryptjs locally and supports cost factors 4 through 12 for interactive use. Raising the cost roughly doubles the work at each step, which slows both legitimate verification and guessing attacks. Generate a fresh hash for every password and never treat bcrypt output as reversible encryption.