Hash Generator

Produce a SHA-1, SHA-256, SHA-384 or SHA-512 digest of any text, using your browser own cryptography engine - nothing you hash is uploaded.

Runs entirely in your browser. Nothing is uploaded.

SHA-1

-

SHA-256

-

SHA-384

-

SHA-512

-

Hashing happens in your browser through the Web Crypto API. Nothing is sent anywhere. SHA-1 is included for checking legacy checksums, not for security.

What a hash is good for

A cryptographic hash turns input of any length into a fixed-length fingerprint. Change one character of the input and the output changes completely, which makes it a reliable way to answer one question: are these two things identical?

That question comes up constantly. Verifying a download matches the checksum a publisher listed. Confirming a file transferred without corruption. Detecting whether a config file changed. Comparing two records without needing to compare the whole contents.

Choosing an algorithm

SHA-256 is the sensible default for anything new. It is widely supported, fast, and has no known practical weakness. SHA-384 and SHA-512 produce longer digests and are worth using where a specification asks for them.

SHA-1 is offered because you will still meet it - older Git objects, legacy checksums, systems that have not been migrated. It is broken for security purposes: practical collision attacks exist, meaning two different inputs can be made to produce the same digest. Use it to verify against an existing SHA-1 value, never to secure something new.

MD5 is not offered at all. It is comprehensively broken, and adding it would mainly serve to keep it alive in new code.

Hashing is not a way to store passwords

A plain SHA-256 of a password is not password storage. These algorithms are designed to be fast, and fast is exactly wrong for passwords: it means an attacker with the digests can try billions of candidates per second on ordinary hardware.

Password storage needs a deliberately slow, salted algorithm - bcrypt, scrypt or Argon2 - where each guess costs real time and identical passwords produce different stored values. Use this tool for checksums and integrity, not for authentication.

Frequently asked questions

Is my input sent to a server?
No. Hashing uses the Web Crypto API built into your browser. The input never leaves your device and nothing is stored.
Can a hash be reversed?
Not directly - hashing is one-way. But short or common inputs can be found by brute force or lookup tables, which is why hashing alone never protects a password.
Which hash should I use?
SHA-256 for anything new. Use SHA-384 or SHA-512 when a specification requires them, and SHA-1 only to verify against an existing legacy value.
Why is MD5 not available?
MD5 is cryptographically broken and collisions are trivial to produce. Offering it would mostly encourage its use in new code where SHA-256 belongs.
Can I use this to check a file download?
Yes - that is the classic use. Hash the content and compare it character by character against the checksum the publisher listed. Any difference at all means the file is not the one they published.