Hash → generator
Type text or drop a file and get MD5, SHA-1, SHA-256, SHA-384 and SHA-512 at once. Paste the checksum from a download page into Verify and the matching row lights up — you do not even need to know which algorithm it was.
- Algorithms
- MD5 · SHA-1 · SHA-2
- Keyed
- HMAC · text or hex key
- Files
- up to 500 MB · never uploaded
Input
Digests
Which algorithm for what
integrity="sha384-…", in Base64) and some TLS suites.Worth knowing
Hashing is not encryption
A hash is a one-way fingerprint: there is no key and no way to turn it back into the input. Encryption is two-way by design. If you need the data back, you want encryption, not a hash.
MD5 and SHA-1 are broken for security
Both have practical collision attacks, so two different files can share a digest. They are still fine for spotting accidental corruption, but not for signatures, certificates or anything an attacker could craft.
Never store passwords with these
General-purpose hashes are built to be fast, which is exactly wrong for passwords — a GPU tries billions a second. Use a slow, salted password hash: Argon2id, bcrypt or scrypt.
Checksums: what they are good for
Compare the SHA-256 published next to a download with the one computed here. If they match, the file arrived intact. It only proves authenticity if the checksum itself came from a source you trust.
One byte changes everything
A trailing newline, Windows \r\n line endings or a different text encoding gives
a completely different digest. Text here is hashed as UTF-8 with \n line breaks,
exactly as it sits in the box.
Why files stop at 500 MB
The browser's built-in SHA functions (WebCrypto) take the whole input in one piece and cannot
stream, so the file has to fit in memory. For multi-gigabyte images use
sha256sum or Get-FileHash locally. Nothing is uploaded either way.
Questions
Can a hash be reversed or decrypted?
No. "MD5 decrypt" sites simply look the hash up in a table of previously hashed common strings. That works for short or common inputs, which is why unsalted fast hashes are unsafe for passwords — not because the hash can be undone.
What is HMAC and when do I need it?
HMAC mixes a secret key into the hash, so only someone holding the key can produce the same value. Webhook signatures (GitHub, Stripe, Slack) and many API request signatures are HMAC-SHA256 of the request body.
Why does my hash differ from the command line?
Usually a newline: echo "abc" | sha256sum hashes abc\n. Use
printf 'abc' or echo -n. Other causes are CRLF line endings or a
file saved in UTF-16 rather than UTF-8.
Is my file uploaded?
No. The file is read and hashed inside this browser tab using WebCrypto and a local MD5 implementation. You can disconnect from the network and it still works.