passwordHashVerify

Verifies a plaintext password against a hash created by passwordHashGenerate(). The algorithm, cost parameters and salt are read from the hash itself. It also verifies hashes created by the deprecated generateBCryptHash() and generateSCryptHash().

passwordHashVerify(password, hash [, algorithm]) → returns boolean

This function requires Adobe ColdFusion 2025 and up.  Not supported on Lucee, etc.

Argument Reference

password string
Required

The plaintext password to verify.

hash string
Required

The stored hash to verify against.

algorithm string

The algorithm the hash was created with.
Values:
  • Argon2
  • BCrypt
  • SCrypt

Compatibility

ColdFusion:

Version 2025+ Introduced in ColdFusion 2025 Update 8. Replaces the deprecated verifyBCryptHash() and verifySCryptHash().

Links more information about passwordHashVerify

Examples
Sample code invoking the passwordHashVerify function

Hashes a password, then checks a correct and a wrong password against the hash.

storedHash = passwordHashGenerate("mySecurePassword");
writeOutput(passwordHashVerify("mySecurePassword", storedHash, "Argon2"));
writeOutput(passwordHashVerify("wrongPassword", storedHash, "Argon2"));

Expected Result: YESNO

Hashes created with generateBCryptHash() can be checked with the new function.

oldHash = generateBCryptHash("myPassword");
writeOutput(passwordHashVerify("myPassword", oldHash, "BCrypt"));

Expected Result: YES

Signup for cfbreak to stay updated on the latest news from the ColdFusion / CFML community. One email, every friday.

Fork me on GitHub