$npx skillfedfor your agent

bcrypt

Modern password hashing for your software and your servers

Worth itPyPI CryptographyReleased Sep 2025212.7M downloads / moApache-2.0Platform wheel

Decision gist · record as of 2026-08-14

platform wheels — bcrypt-5.0.0-cp313-cp313t-macosx_10_12_universal2.whl · bcrypt-5.0.0-cp313-cp313t-manylinux2014_aarch64.manylinux_2_17_aarch64.whl · bcrypt-5.0.0-cp313-cp313t-manylinux2014_x86_64.manylinux_2_17_x86_64.whl
v5.0.0 · released 2025-09-25 · Python >=3.8

Yes. bcrypt is production-stable, actively maintained, widely used (top 1000 PyPI packages), has no known vulnerabilities, and solves the core password-hashing problem well. Install it if you need bcrypt specifically; if you're choosing a password hashing algorithm fresh, evaluate argon2id or scrypt as documented alternatives, but bcrypt remains a solid choice for most applications.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires a C compiler and Rust compiler (minimum 1.74) when building from source; pre-built wheels available for most platforms.
  • Medium install friction due to Rust and C compiler requirements at build time.
  • The package is actively maintained with recent releases and broad platform support via pre-built wheels for most Python versions and architectures.

License · maintenance · safety

Apache-2.0 (permissive) — Apache-2.0 is permissive and places minimal restrictions on use, modification, and distribution in both open-source and commercial contexts.

last release 2025-09-25 (323 days) · last repo commit 2026-08-13 · 1,499 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 212,710,127 downloads/mo, #194 on PyPI

Verify before relying

pip install bcrypt

import bcrypt
password = b"super secret password"
hashed = bcrypt.hashpw(password, bcrypt.gensalt())
if bcrypt.checkpw(password, hashed):
    print("Password matches")
  • Whether the 72-byte password limit is acceptable for your use case without pre-hashing
  • Performance characteristics compared to argon2id or scrypt for your workload
Same gist for agents: .md · .json

What it is and what it does

bcrypt is a Python library that implements the bcrypt password hashing algorithm, which applies a salted hash with an adjustable work factor to securely store passwords. It wraps the OpenBSD bcrypt implementation and is written in Rust for performance and safety. The library provides three main functions: hashpw() to hash a password with a generated salt, checkpw() to verify a plaintext password against a stored hash, and kdf() to derive cryptographic keys using bcrypt_pbkdf.

The package is designed for password storage in web applications and servers. It supports adjustable rounds (work factor) to increase computational cost over time as hardware improves, and allows control over the hash prefix for compatibility with different bcrypt implementations. The library acknowledges that while bcrypt remains acceptable, argon2id and scrypt may be preferable for some use cases.

Use it for

  • Store user passwords securely in web applications with automatic salt generation and verification
  • Implement password verification during login by comparing plaintext input against stored bcrypt hashes
  • Derive encryption keys from passwords using bcrypt_pbkdf for OpenSSH-compatible key formats
  • Adjust computational cost of password hashing over time by increasing rounds as hardware performance improves
  • Maintain compatibility with existing bcrypt-hashed password databases across different systems

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

bcrypt is production-stable, actively maintained, widely used (top 1000 PyPI packages), has no known vulnerabilities, and solves the core password-hashing problem well. Install it if you need bcrypt specifically; if you're choosing a password hashing algorithm fresh, evaluate argon2id or scrypt as documented alternatives, but bcrypt remains a solid choice for most applications.

Install

bcrypt on PyPI

Before you install

Medium install friction due to Rust and C compiler requirements at build time. The package is actively maintained with recent releases and broad platform support via pre-built wheels for most Python versions and architectures.

Requires a C compiler and Rust compiler (minimum 1.74) when building from source; pre-built wheels available for most platforms.

License in practice

Apache-2.0 is permissive and places minimal restrictions on use, modification, and distribution in both open-source and commercial contexts.

Quickstart

pip install bcrypt

import bcrypt
password = b"super secret password"
hashed = bcrypt.hashpw(password, bcrypt.gensalt())
if bcrypt.checkpw(password, hashed):
    print("Password matches")

Verify before relying

  • Whether the 72-byte password limit is acceptable for your use case without pre-hashing
  • Performance characteristics compared to argon2id or scrypt for your workload

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release >=3.8
Install frictionMedium. Platform-specific wheel
Runtime dependenciesNone
MaintenanceActively maintained 323 days since the last release
Last repo commit
First released
Downloads212,710,127 / month, #194 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Free Threading :: 3 - StableProgramming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPy

Evidence: bcrypt-5.0.0-cp313-cp313t-macosx_10_12_universal2.whl; bcrypt-5.0.0-cp313-cp313t-manylinux2014_aarch64.manylinux_2_17_aarch64.whl; bcrypt-5.0.0-cp313-cp313t-manylinux2014_x86_64.manylinux_2_17_x86_64.whl; bcrypt-5.0.0-cp313-cp313t-manylinux_2_28_aarch64.whl; bcrypt-5.0.0-cp313-cp313t-manylinux_2_28_armv7l.manylinux_2_31_armv7l.whl; bcrypt-5.0.0-cp313-cp313t-manylinux_2_28_x86_64.whl; bcrypt-5.0.0-cp313-cp313t-manylinux_2_34_aarch64.whl; bcrypt-5.0.0-cp313-cp313t-manylinux_2_34_x86_64.whl; bcrypt-5.0.0-cp313-cp313t-musllinux_1_1_aarch64.whl; bcrypt-5.0.0-cp313-cp313t-musllinux_1_1_x86_64.whl; bcrypt-5.0.0-cp313-cp313t-musllinux_1_2_aarch64.whl; bcrypt-5.0.0-cp313-cp313t-musllinux_1_2_x86_64.whl; bcrypt-5.0.0-cp313-cp313t-win32.whl; bcrypt-5.0.0-cp313-cp313t-win_amd64.whl; bcrypt-5.0.0-cp313-cp313t-win_arm64.whl; bcrypt-5.0.0-cp314-cp314t-macosx_10_12_universal2.whl; bcrypt-5.0.0-cp314-cp314t-manylinux2014_aarch64.manylinux_2_17_aarch64.whl; bcrypt-5.0.0-cp314-cp314t-manylinux2014_x86_64.manylinux_2_17_x86_64.whl; bcrypt-5.0.0-cp314-cp314t-manylinux_2_28_aarch64.whl; bcrypt-5.0.0-cp314-cp314t-manylinux_2_28_armv7l.manylinux_2_31_armv7l.whl

Tags

Capabilities
password hashingbcrypt passwordsecure password storagepassword verificationkey derivation functioncryptographic hashingpassword checksum
Topics
password-hashingcryptography

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “bcrypt password”

  • bcryptbcrypt provides modern password hashing using the bcrypt algorithm,…
  • Flask-BcryptFlask-Bcrypt wraps the bcrypt password-hashing library for use in…
  • AuthEncodingAuthEncoding provides a framework for creating, validating, and…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also AuthEncoding · Flask-Bcrypt · pwdlib · libpass · passlib · password-strength · pysodium · pyscrypt · altcha