Search tools

Hash Generator

Get the SHA-256, SHA-512, SHA-1 and MD5 hash of any text or file, and check a download's checksum.

Runs entirely in your browser. Nothing you paste is sent to our server, stored or logged.

Hashes

Type text or choose a file and every common hash appears at once: SHA-256, SHA-384, SHA-512, SHA-1 and MD5. Add a key to get an HMAC instead, or paste a published checksum to check that a download has not been changed or corrupted. Files are hashed on your computer, so even large or private ones never leave it.

What a hash is

A hash function turns any input into a short, fixed length fingerprint. The same input always gives the same hash, while changing a single character changes it completely, and there is no way to work back from the hash to the input. That makes hashes the standard way to check that a file arrived intact.

Which algorithm to use

Use SHA-256 unless something else is required; it is the default for checksums, Git's newer object format and most signatures. SHA-512 is just as safe and can be faster on 64 bit machines. MD5 and SHA-1 are broken: it is possible to make two different files with the same hash, so keep them for old systems and simple checksums, never for security.

Hashes, HMACs and passwords

A plain hash proves that data has not changed by accident. An HMAC mixes in a secret key, so it also proves who made it; webhooks and APIs use it to sign requests. Neither is right for storing passwords, which need a deliberately slow function such as Argon2 or bcrypt.

How to use the hash generator

  1. Enter text or choose a fileType or paste text, or choose a file from your computer. Every hash updates as you go.
  2. Add a key for an HMACOptional: with a key, each result becomes an HMAC with that algorithm.
  3. Check a checksumPaste the checksum a website publishes to see whether it matches.

Common questions

How do I check the SHA-256 of a downloaded file?

Choose the file, then paste the checksum from the download page into the checksum box. The page tells you if it matches the file's SHA-256 or any other hash shown. The file is read on your computer and never uploaded.

Can a hash be reversed or decrypted?

No. A hash is not encryption; there is no key and no way back. Short or common inputs can be found by guessing, which is why passwords need a slow hashing function and a salt.

Why is MD5 still offered if it is broken?

Many older systems and download sites still publish MD5 checksums, and it is fine for catching accidental corruption. It is not safe where someone might create a forged file on purpose, so prefer SHA-256 whenever you have the choice.

What is an HMAC?

A hash that also depends on a secret key. Only someone with the key can produce the same value, so services such as GitHub and Stripe use HMAC-SHA256 to sign webhooks, and the receiver checks it with the shared secret.

Does the hash depend on the text encoding?

Yes. Text is hashed as UTF-8, the encoding nearly every system uses. The same words saved as UTF-16 or with Windows line endings are different bytes and give a different hash.

Is my text or file uploaded?

No. Hashing happens in your browser with its built in cryptography, and nothing you enter, including an HMAC key, is sent to our server.