The bcrypt algorithm used by PHP silently truncates passwords after 72 bytes. Some C libraries also stop at the first NUL byte. The new PASSWORD_BCRYPT_SHA256 identifier avoids both limits while keeping PASSWORD_BCRYPT unchanged.
How it works
The algorithm first computes an HMAC-SHA256 using the bcrypt salt as the key and the password as the message. It then Base64-encodes that fixed-size digest before passing it to bcrypt. The resulting hash uses the same format as Passlib's bcrypt_sha256 version 2, so PHP and Python applications can share hashes.
$hash = password_hash($password, PASSWORD_BCRYPT_SHA256); var_dump(password_verify($password, $hash)); // true
The new identifier works with password_hash(), password_verify(), password_needs_rehash(), password_get_info(), and password_algos(). It accepts the same cost range as PASSWORD_BCRYPT, from 4 to 31, with a default of 12.
What changes for existing code
This is an opt-in algorithm. PASSWORD_BCRYPT, PASSWORD_ARGON2I, PASSWORD_ARGON2ID, and PASSWORD_DEFAULT keep their current behavior. Applications switching to the new algorithm should check that their database column can hold the longer bcrypt-sha256 string.
The proposal also adds a small internal HMAC helper in ext/hash for the password implementation to use. The proof-of-concept pull request contains the implementation. The RFC follows the earlier proposal to reject bcrypt passwords over 72 bytes, but does not change the behavior of existing bcrypt hashes.
Where it stands
Sjoerd Langkemper published the draft on October 4, 2026, targeting PHP 8.7. The proof-of-concept implementation is available in the pull request. The RFC has not opened its vote yet. A future primary vote needs a two-thirds majority to pass.