bcrypt
Modern password hashing for your software and your servers
Decision gist · record as of 2026-08-14
Yes. bcrypt is production-stable, actively maintained, widely used (top 1000 PyPI packages), has no known vulnerabilities, and solves the core password-hashing problem well. Install it if you need bcrypt specifically; if you're choosing a password hashing algorithm fresh, evaluate argon2id or scrypt as documented alternatives, but bcrypt remains a solid choice for most applications.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a C compiler and Rust compiler (minimum 1.74) when building from source; pre-built wheels available for most platforms.
- Medium install friction due to Rust and C compiler requirements at build time.
- The package is actively maintained with recent releases and broad platform support via pre-built wheels for most Python versions and architectures.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 is permissive and places minimal restrictions on use, modification, and distribution in both open-source and commercial contexts.
last release 2025-09-25 (323 days) · last repo commit 2026-08-13 · 1,499 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 212,710,127 downloads/mo, #194 on PyPI
Alternatives
Verify before relying
pip install bcrypt
import bcrypt
password = b"super secret password"
hashed = bcrypt.hashpw(password, bcrypt.gensalt())
if bcrypt.checkpw(password, hashed):
print("Password matches")- Whether the 72-byte password limit is acceptable for your use case without pre-hashing
- Performance characteristics compared to argon2id or scrypt for your workload
What it is and what it does
bcrypt is a Python library that implements the bcrypt password hashing algorithm, which applies a salted hash with an adjustable work factor to securely store passwords. It wraps the OpenBSD bcrypt implementation and is written in Rust for performance and safety. The library provides three main functions: hashpw() to hash a password with a generated salt, checkpw() to verify a plaintext password against a stored hash, and kdf() to derive cryptographic keys using bcrypt_pbkdf.
The package is designed for password storage in web applications and servers. It supports adjustable rounds (work factor) to increase computational cost over time as hardware improves, and allows control over the hash prefix for compatibility with different bcrypt implementations. The library acknowledges that while bcrypt remains acceptable, argon2id and scrypt may be preferable for some use cases.
Use it for
- Store user passwords securely in web applications with automatic salt generation and verification
- Implement password verification during login by comparing plaintext input against stored bcrypt hashes
- Derive encryption keys from passwords using bcrypt_pbkdf for OpenSSH-compatible key formats
- Adjust computational cost of password hashing over time by increasing rounds as hardware performance improves
- Maintain compatibility with existing bcrypt-hashed password databases across different systems
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
bcrypt is production-stable, actively maintained, widely used (top 1000 PyPI packages), has no known vulnerabilities, and solves the core password-hashing problem well. Install it if you need bcrypt specifically; if you're choosing a password hashing algorithm fresh, evaluate argon2id or scrypt as documented alternatives, but bcrypt remains a solid choice for most applications.
Install
bcrypt on PyPI
Before you install
Medium install friction due to Rust and C compiler requirements at build time. The package is actively maintained with recent releases and broad platform support via pre-built wheels for most Python versions and architectures.
Requires a C compiler and Rust compiler (minimum 1.74) when building from source; pre-built wheels available for most platforms.
License in practice
Apache-2.0 is permissive and places minimal restrictions on use, modification, and distribution in both open-source and commercial contexts.
Quickstart
pip install bcrypt
import bcrypt
password = b"super secret password"
hashed = bcrypt.hashpw(password, bcrypt.gensalt())
if bcrypt.checkpw(password, hashed):
print("Password matches")
Verify before relying
- Whether the 72-byte password limit is acceptable for your use case without pre-hashing
- Performance characteristics compared to argon2id or scrypt for your workload
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 323 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 212,710,127 / month, #194 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Free Threading :: 3 - StableProgramming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPy |
Evidence: bcrypt-5.0.0-cp313-cp313t-macosx_10_12_universal2.whl; bcrypt-5.0.0-cp313-cp313t-manylinux2014_aarch64.manylinux_2_17_aarch64.whl; bcrypt-5.0.0-cp313-cp313t-manylinux2014_x86_64.manylinux_2_17_x86_64.whl; bcrypt-5.0.0-cp313-cp313t-manylinux_2_28_aarch64.whl; bcrypt-5.0.0-cp313-cp313t-manylinux_2_28_armv7l.manylinux_2_31_armv7l.whl; bcrypt-5.0.0-cp313-cp313t-manylinux_2_28_x86_64.whl; bcrypt-5.0.0-cp313-cp313t-manylinux_2_34_aarch64.whl; bcrypt-5.0.0-cp313-cp313t-manylinux_2_34_x86_64.whl; bcrypt-5.0.0-cp313-cp313t-musllinux_1_1_aarch64.whl; bcrypt-5.0.0-cp313-cp313t-musllinux_1_1_x86_64.whl; bcrypt-5.0.0-cp313-cp313t-musllinux_1_2_aarch64.whl; bcrypt-5.0.0-cp313-cp313t-musllinux_1_2_x86_64.whl; bcrypt-5.0.0-cp313-cp313t-win32.whl; bcrypt-5.0.0-cp313-cp313t-win_amd64.whl; bcrypt-5.0.0-cp313-cp313t-win_arm64.whl; bcrypt-5.0.0-cp314-cp314t-macosx_10_12_universal2.whl; bcrypt-5.0.0-cp314-cp314t-manylinux2014_aarch64.manylinux_2_17_aarch64.whl; bcrypt-5.0.0-cp314-cp314t-manylinux2014_x86_64.manylinux_2_17_x86_64.whl; bcrypt-5.0.0-cp314-cp314t-manylinux_2_28_aarch64.whl; bcrypt-5.0.0-cp314-cp314t-manylinux_2_28_armv7l.manylinux_2_31_armv7l.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “bcrypt password”
- bcryptbcrypt provides modern password hashing using the bcrypt algorithm,…
- Flask-BcryptFlask-Bcrypt wraps the bcrypt password-hashing library for use in…
- AuthEncodingAuthEncoding provides a framework for creating, validating, and…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also AuthEncoding · Flask-Bcrypt · pwdlib · libpass · passlib · password-strength · pysodium · pyscrypt · altcha