Sample code for 30+ languages & platforms
SQL Server

BCrypt Verify a Password (Check if Password is Correct)

See more Encryption Examples

A system that uses BCrypt for storing passwords would not store the actual password, but would instead store the bcrypt hash of the password. When a user presents the password, such as for login, call BCryptVerify to verify the password against the stored bcrypt hash.

Note: This example requires Chilkat v9.5.0.65 or greater.

Chilkat SQL Server Downloads

SQL Server
-- Important: See this note about string length limitations for strings returned by sp_OAMethod calls.
--
CREATE PROCEDURE ChilkatSample
AS
BEGIN
    DECLARE @hr int
    -- This example assumes the Chilkat API to have been previously unlocked.
    -- See Global Unlock Sample for sample code.

    DECLARE @crypt int
    EXEC @hr = sp_OACreate 'Chilkat.Crypt2', @crypt OUT
    IF @hr <> 0
    BEGIN
        PRINT 'Failed to create ActiveX component'
        RETURN
    END

    DECLARE @storedHash nvarchar(4000)
    SELECT @storedHash = '$2a$10$H5kIVktMGzAPKGKNAe9DVu0iwEqfhv/o4MMJ/Dzw/MPy1leOE9NOK'
    DECLARE @password nvarchar(4000)
    SELECT @password = 'mySecretPassword'

    DECLARE @passwordValid int
    EXEC sp_OAMethod @crypt, 'BCryptVerify', @passwordValid OUT, @password, @storedHash
    IF @passwordValid = 1
      BEGIN

        PRINT @password + ' is valid.'
      END
    ELSE
      BEGIN

        PRINT @password + ' is NOT valid.'
      END

    SELECT @password = 'notAValidPassword'
    EXEC sp_OAMethod @crypt, 'BCryptVerify', @passwordValid OUT, @password, @storedHash
    IF @passwordValid = 1
      BEGIN

        PRINT @password + ' is valid.'
      END
    ELSE
      BEGIN

        PRINT @password + ' is NOT valid.'
      END

    -- Output should be:

    -- 	mySecretPassword is valid.
    -- 	notAValidPassword is NOT valid.

    EXEC @hr = sp_OADestroy @crypt


END
GO