Skip to content
Toolbench

Hash Generator

Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes, or verify a checksum.

Runs entirely in your browser

Loading tool...

How to use

  1. Pick an algorithm. SHA-256 is the right default; MD5 and SHA-1 are for checking files someone else hashed.
  2. Type or paste your text. The hash updates as you type.
  3. To verify a download, paste the published checksum into the compare field and look for the match.
  4. Copy the result, or switch algorithms to compare them side by side.

Features

  • MD5, SHA-1, SHA-256, SHA-384 and SHA-512 from one input.
  • Checksum comparison that ignores case and stray whitespace, because a pasted checksum has both.
  • A plain warning on the algorithms that are no longer safe to trust.
  • Runs entirely in your browser — the text never leaves the device.
  • Correct on multi-byte text: Vietnamese, Japanese and emoji hash the same as any other tool.

Frequently asked questions

Is my text sent to a server?
No. SHA hashing uses the browser's built-in Web Crypto, and MD5 runs in the page. Nothing is uploaded, which is what makes this safe for anything sensitive.
Should I use MD5?
Only to check a file against a checksum someone published. MD5 and SHA-1 are both broken — two different inputs can be made to produce the same hash — so they must never protect a password, a signature or anything an attacker benefits from forging. Use SHA-256 for that.
Can I hash a password with this?
You can, but you should not store the result. A password needs a slow, salted algorithm such as scrypt, bcrypt or Argon2; a plain hash of a password can be reversed with a lookup table in seconds.
Why does my hash differ from another tool's?
Almost always a difference in the input rather than the algorithm: a trailing newline, different line endings, or text encoded as something other than UTF-8. This tool hashes exactly the characters you enter, encoded UTF-8.

Encrypt a note with a password, in your browser — AES-GCM with a properly derived key, not a toy cipher.

Sign a message with a secret key, or check a webhook signature you were sent.

What kind of hash is this? A ranked shortlist, and an honest note about when the answer cannot be known.

Generate strong random passwords.