zerouploads

Hash Generator

MD5, SHA-1, SHA-256, SHA-384 and SHA-512 digests of text or a file, worked out in your browser.

  • Preview
  • Unlimited
  • No signup
  • Private
  • Works offline

Hash text or a file

What to hash

43 characters · 43 bytes UTF-8hashed on every keystroke

Digest settings
Every digest of the current input, one algorithm per row
AlgorithmLengthDigestCopy
Digests appear here.

MD5 and SHA-1 are here for checksum compatibility only. Both have practical collision attacks.

43 bytes hashed · 0 digests · computed in this tab

Which algorithm to use

SHA-256 is the right answer for almost everything. It is fast, every language and tool supports it, and nobody has broken it. SHA-384 and SHA-512 give longer digests. On 64-bit hardware SHA-512 is often faster than SHA-256, even though its output is twice as long.

MD5 and SHA-1 are here because many systems still use them. Older APIs print them, download pages list them, and legacy databases are full of them. Both are broken, and neither should protect anything that matters.

Broken means someone can build two different inputs with the same digest. For MD5 that takes seconds on an ordinary laptop. So it is fine for spotting a file that got damaged on the way down. It is useless against anyone trying to fool you on purpose.

Algorithms
MD5, SHA-1, SHA-256, SHA-384 and SHA-512, plus the HMAC version of each SHA.
Input
Text in UTF-8 or Latin-1, or a file read as raw bytes. A file is held in memory once.
Output
Lowercase hex, uppercase hex or Base64. Paste a checksum in and it says which one matches.
Engine
Your browser's Web Crypto, except for MD5. Web Crypto leaves MD5 out, so this page computes it itself.

Hashing is not password storage

A SHA-256 of a password is quick to work out, which is exactly the wrong property. Someone with a stolen list can try billions of guesses an hour. Passwords need a slow, salted function built for the job: bcrypt, scrypt or Argon2.

Use this tool to check a download, compare two files, build a cache key, or see whether two things are the same. Do not use it to build a login.

Frequently asked questions

Is my input sent to a server to be hashed?
No. Digests are worked out by your own browser, so passwords, tokens and private files stay on your machine. There is no request to make and nothing to log.
Which hash should I use?
SHA-256, unless something else told you otherwise. It is the default for signatures, checksums and integrity checks. Use MD5 or SHA-1 only when you are matching a digest that already exists.
Why are MD5 and SHA-1 marked legacy?
Because two different files can be made to share a digest, and for MD5 that is now cheap. Where the point is to stop someone tampering, those two do not stop them. Turn off Show deprecated algorithms to hide them.
Can I hash a large file?
As large as your device's memory allows. Web Crypto hashes the whole file in one go, so the file has to fit in memory.
Can I check a checksum against mine?
Yes. Paste it into Compare with a digest. The row it matches is marked, so you learn both that it matches and which algorithm made it. A whole SHA256SUMS line works too.
What is HMAC for?
It signs a message with a shared secret, so the person reading it can tell it came from you and was not changed. Webhooks use it. The secret is held in memory for the signing and never stored.
Should I hash passwords with this?
No. Use bcrypt, scrypt or Argon2 in your own code. Those are slow and salted on purpose, which is what makes a stolen list hard to crack.
Browse all developer tools