Skip to content
Browse tools

Hash → generator

Type text or drop a file and get MD5, SHA-1, SHA-256, SHA-384 and SHA-512 at once. Paste the checksum from a download page into Verify and the matching row lights up — you do not even need to know which algorithm it was.

Algorithms
MD5 · SHA-1 · SHA-2
Keyed
HMAC · text or hex key
Files
up to 500 MB · never uploaded
Step 1

Input

empty
Hash
drop a file to hash it
Step 2

Digests

Output
5 algorithms
AlgorithmDigest
Nothing to hash yet Type or paste text, or open a file.

Which algorithm for what

AlgorithmOutputUse it for
MD5128 bit · 32 hexLegacy checksums and cache keys only. Collisions can be produced in seconds — never for security.
SHA-1160 bit · 40 hexOld Git object ids and legacy systems. A real collision was published in 2017; retire it for signatures.
SHA-256256 bit · 64 hexThe default today: download checksums, signatures, HMAC-SHA256 for webhooks and APIs.
SHA-384384 bit · 96 hexSubresource Integrity (integrity="sha384-…", in Base64) and some TLS suites.
SHA-512512 bit · 128 hexSame family as SHA-256 with a longer output; often faster than SHA-256 on 64-bit CPUs.

Worth knowing

Hashing is not encryption

A hash is a one-way fingerprint: there is no key and no way to turn it back into the input. Encryption is two-way by design. If you need the data back, you want encryption, not a hash.

MD5 and SHA-1 are broken for security

Both have practical collision attacks, so two different files can share a digest. They are still fine for spotting accidental corruption, but not for signatures, certificates or anything an attacker could craft.

Never store passwords with these

General-purpose hashes are built to be fast, which is exactly wrong for passwords — a GPU tries billions a second. Use a slow, salted password hash: Argon2id, bcrypt or scrypt.

Checksums: what they are good for

Compare the SHA-256 published next to a download with the one computed here. If they match, the file arrived intact. It only proves authenticity if the checksum itself came from a source you trust.

One byte changes everything

A trailing newline, Windows \r\n line endings or a different text encoding gives a completely different digest. Text here is hashed as UTF-8 with \n line breaks, exactly as it sits in the box.

Why files stop at 500 MB

The browser's built-in SHA functions (WebCrypto) take the whole input in one piece and cannot stream, so the file has to fit in memory. For multi-gigabyte images use sha256sum or Get-FileHash locally. Nothing is uploaded either way.

Questions

Can a hash be reversed or decrypted?

No. "MD5 decrypt" sites simply look the hash up in a table of previously hashed common strings. That works for short or common inputs, which is why unsalted fast hashes are unsafe for passwords — not because the hash can be undone.

What is HMAC and when do I need it?

HMAC mixes a secret key into the hash, so only someone holding the key can produce the same value. Webhook signatures (GitHub, Stripe, Slack) and many API request signatures are HMAC-SHA256 of the request body.

Why does my hash differ from the command line?

Usually a newline: echo "abc" | sha256sum hashes abc\n. Use printf 'abc' or echo -n. Other causes are CRLF line endings or a file saved in UTF-16 rather than UTF-8.

Is my file uploaded?

No. The file is read and hashed inside this browser tab using WebCrypto and a local MD5 implementation. You can disconnect from the network and it still works.