Sample code for 30+ languages & platforms
PHP Extension

BCrypt Verify a Password (Check if Password is Correct)

See more Encryption Examples

A system that uses BCrypt for storing passwords would not store the actual password, but would instead store the bcrypt hash of the password. When a user presents the password, such as for login, call BCryptVerify to verify the password against the stored bcrypt hash.

Note: This example requires Chilkat v9.5.0.65 or greater.

Chilkat PHP Extension Downloads

PHP Extension
<?php

include("chilkat.php");

// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

$crypt = new CkCrypt2();

$storedHash = '$2a$10$H5kIVktMGzAPKGKNAe9DVu0iwEqfhv/o4MMJ/Dzw/MPy1leOE9NOK';
$password = 'mySecretPassword';

$passwordValid = $crypt->BCryptVerify($password,$storedHash);
if ($passwordValid == true) {
    print $password . ' is valid.' . "\n";
}
else {
    print $password . ' is NOT valid.' . "\n";
}

$password = 'notAValidPassword';
$passwordValid = $crypt->BCryptVerify($password,$storedHash);
if ($passwordValid == true) {
    print $password . ' is valid.' . "\n";
}
else {
    print $password . ' is NOT valid.' . "\n";
}

// Output should be:

// 	mySecretPassword is valid.
// 	notAValidPassword is NOT valid.

?>