Hash Generator
Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes, or verify a checksum.
Runs entirely in your browser
Loading tool...
How to use
- Pick an algorithm. SHA-256 is the right default; MD5 and SHA-1 are for checking files someone else hashed.
- Type or paste your text. The hash updates as you type.
- To verify a download, paste the published checksum into the compare field and look for the match.
- Copy the result, or switch algorithms to compare them side by side.
Features
- MD5, SHA-1, SHA-256, SHA-384 and SHA-512 from one input.
- Checksum comparison that ignores case and stray whitespace, because a pasted checksum has both.
- A plain warning on the algorithms that are no longer safe to trust.
- Runs entirely in your browser — the text never leaves the device.
- Correct on multi-byte text: Vietnamese, Japanese and emoji hash the same as any other tool.
Frequently asked questions
- Is my text sent to a server?
- No. SHA hashing uses the browser's built-in Web Crypto, and MD5 runs in the page. Nothing is uploaded, which is what makes this safe for anything sensitive.
- Should I use MD5?
- Only to check a file against a checksum someone published. MD5 and SHA-1 are both broken — two different inputs can be made to produce the same hash — so they must never protect a password, a signature or anything an attacker benefits from forging. Use SHA-256 for that.
- Can I hash a password with this?
- You can, but you should not store the result. A password needs a slow, salted algorithm such as scrypt, bcrypt or Argon2; a plain hash of a password can be reversed with a lookup table in seconds.
- Why does my hash differ from another tool's?
- Almost always a difference in the input rather than the algorithm: a trailing newline, different line endings, or text encoded as something other than UTF-8. This tool hashes exactly the characters you enter, encoded UTF-8.
Related tools
Encrypt a note with a password, in your browser — AES-GCM with a properly derived key, not a toy cipher.
Sign a message with a secret key, or check a webhook signature you were sent.
What kind of hash is this? A ranked shortlist, and an honest note about when the answer cannot be known.
Generate strong random passwords.