OSS Tanbou

generate password hashes in Python and verify them against salted bcrypt hashes

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
1,500
Primary language
Python
License
Apache-2.0
Repository last updated
Sep 25, 2026
On this page

Overview

bcrypt is a Python library for generating and verifying bcrypt password hashes. gensalt and hashpw create salted hashes, while checkpw compares an entered password with a stored hash. It also exposes an adjustable work factor and a bcrypt_pbkdf-based KDF.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Generate salted password hashes and verify them

Use bcrypt.gensalt() to generate a salt, hashpw to create the stored password hash, and checkpw during authentication to compare an entered password with that hash.

Sources: [2]

Adjust the work factor and use bcrypt_pbkdf when needed

The rounds argument to gensalt adjusts computational cost, while the kdf function exposes bcrypt_pbkdf for separate key-derivation use cases.

Sources: [2]

Best fit

Fits Python systems that need compatibility with existing bcrypt password hashes

It is useful when an existing authentication system already stores bcrypt hashes or when Python code must continue generating and checking the same hash format.

Sources: [2]

Before adoption

Compare Argon2id or scrypt for new password-storage designs

The upstream README describes bcrypt as acceptable while explicitly pointing users toward Argon2id or scrypt depending on the use case. New password-storage designs should compare those options rather than choosing bcrypt only for familiarity.

Sources: [2]

Version 5.0.0 raises ValueError for passwords over 72 bytes

In 5.0.0, inputs longer than 72 bytes are no longer silently truncated and instead raise ValueError. Existing applications that accept long passwords should verify upgrade behavior. The stable 5.0.0 package metadata targets Python 3.8+.

Sources: [3][4]

Official sources

  1. [1]pyca/bcrypt repository(2026-09-30)
  2. [2]bcrypt 5.0.0 README(2026-09-30)
  3. [3]bcrypt 5.0.0 package metadata(2026-09-30)
  4. [4]bcrypt changelog(2026-09-30)
  5. [5]bcrypt Apache-2.0 license(2026-09-30)
Supplemental curator note

bcrypt remains practical when a Python system must preserve compatibility with existing bcrypt hashes, while the upstream README also points new designs toward comparing Argon2id or scrypt. Version 5.0.0 changes how inputs over 72 bytes are handled.

Try it in 3 steps

  1. 1

    Install bcrypt 5.0.0

    Add the stable release to a Python project with the version pinned.

    python -m pip install bcrypt==5.0.0
  2. 2

    Hash a password

    Generate a random salt and create the stored hash. Do not store the plaintext password.

    import bcrypt password = b"super secret password" hashed = bcrypt.hashpw(password, bcrypt.gensalt())
  3. 3

    Verify against the stored hash

    Compare the entered password with the stored hash during authentication. In 5.0.0, passwords over 72 bytes raise ValueError, so validate upgrade behavior.

    bcrypt.checkpw(password, hashed)
Check the official README

Growth

Growth trends · Last 30 days

1,500 Stars

Trend data is still being collected.

Built with

Categories and tags

Categories

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • python
Stars
1,500
Forks
216
Watchers
25
Open issues
7
Owner type
Organization
Primary language
Python
License
Apache-2.0
Repository last updated
Sep 25, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?