Skip to content

Runs entirely in your browser. Nothing you paste leaves this page.

Free / No sign-up

Hash generator: SHA-256, SHA-512 and MD5 online.

Compute SHA-256, SHA-512, SHA-384, SHA-1 and MD5 hashes of text or files, and verify a download against its published checksum. Files never leave your device.

Input type
  • SHA-1legacy

    ...
  • SHA-256

    ...
  • SHA-384

    ...
  • SHA-512

    ...
  • MD5insecure

    ...

SHA hashes use your browser's Web Crypto API. MD5 is computed by our own implementation for checksums only: it is broken for security and must never protect passwords or signatures.

How to use it.

  1. 01

    Type text, or switch to File and drop in a file of up to 200 MB.

  2. 02

    MD5, SHA-1, SHA-256, SHA-384 and SHA-512 are computed at once; copy the one you need.

  3. 03

    Paste an expected checksum to confirm a download is intact. The matching algorithm is highlighted.

What it does.

Everything this tool handles, all of it inside your browser tab.

  • MD5, SHA-1, SHA-256, SHA-384 and SHA-512 computed at once
  • Hash text as UTF-8, or any file up to 200 MB
  • Drag and drop files; they are read locally and never uploaded
  • Checksum compare box that highlights which algorithm matches
  • Lowercase or uppercase hex output
  • SHA family through the browser's Web Crypto API, MD5 through an RFC 1321 implementation
  • Insecure and legacy algorithms clearly labelled
  • One-click copy for every digest

Worked examples.

  • SHA-256 of a string

    Input:    hello
    SHA-256:  2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824

    64 hexadecimal characters, always, whatever the input length. Type hello above and compare.

  • Why a trailing newline changes the hash

    hello      → 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
    hello + \n → 5891b5b522d5df086d0ff0b110fbd9d21bb4fc7163af34d08286a2e846f6be03
    
    $ echo "hello" | sha256sum     # adds a newline
    $ printf 'hello' | sha256sum   # matches this tool

    One invisible character produces a completely different digest. This is the most common reason two tools disagree.

  • MD5, SHA-1 and SHA-256 of the same input

    Input:    abc
    MD5:      900150983cd24fb0d6963f7d28e17f72
    SHA-1:    a9993e364706816aba3e25717850c26c9cd0d89d
    SHA-256:  ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad

    These are the official test vectors from RFC 1321 and FIPS 180, so any correct implementation gives exactly these values.

  • MD5 hash of an empty string

    MD5('')     = d41d8cd98f00b204e9800998ecf8427e
    SHA-256('') = e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

    If you see these values in logs or a database, something hashed an empty input, often a missing field or an empty upload.

  • Check a file's SHA-256 on the command line

    Linux       sha256sum installer.iso
    macOS       shasum -a 256 installer.iso
    PowerShell  Get-FileHash installer.iso -Algorithm SHA256
    Windows     certutil -hashfile installer.iso SHA256

    Each prints the same digest this page shows in File mode. Compare it with the checksum on the publisher's site.

What is a hash function?

A cryptographic hash function turns any input, from one letter to a multi-gigabyte file, into a short fixed-length fingerprint called a digest. The same input always gives the same digest, and changing a single bit changes about half of the output bits, the avalanche effect. SHA-256 always produces 256 bits, written as 64 hexadecimal characters; MD5 gives 32 characters, SHA-1 40, SHA-384 96 and SHA-512 128.

A secure hash has three properties. Preimage resistance: given a digest, you cannot find an input that produces it. Second-preimage resistance: given one input, you cannot find another with the same digest. Collision resistance: you cannot find any two inputs with the same digest. When the last property breaks, the hash is no longer safe for signatures or certificates.

MD5 vs SHA-1 vs SHA-256 vs SHA-512

MD5 (RFC 1321, 1992) has been broken since 2004, when practical collisions were published; chosen-prefix collisions followed and were used to forge a code-signing certificate in the Flame malware. SHA-1 fell in 2017, when the first public collision was demonstrated, and NIST has scheduled it for retirement. Both remain fine for spotting accidental corruption or as cache keys, but never for anything an attacker could tamper with.

SHA-256, SHA-384 and SHA-512 belong to the SHA-2 family (FIPS 180-4) and have no practical attacks. SHA-256 is the everyday default for checksums, Git's newer object format, software supply chains and digital signatures. SHA-384 and SHA-512 offer longer digests and appear in TLS cipher suites and Subresource Integrity attributes. SHA-3 (FIPS 202) is a different design kept as an alternative; it is not offered here because the browser's Web Crypto API does not provide it.

One subtle point: MD5, SHA-1, SHA-256 and SHA-512 are all vulnerable to length-extension, so hash(secret + message) is not a safe way to sign a message. Use HMAC, for example HMAC-SHA256, which is built for message authentication and is what signs JWTs with HS256 and most webhook payloads.

How to verify a file checksum

Software publishers list a SHA-256 checksum next to a download so you can confirm the file you received is byte-for-byte the file they released. Switch to File, drop the download in, and paste the published checksum into the compare box. A green match tells you the file is complete and unmodified; no match means a corrupted or different file, so download it again from the official source.

A checksum proves integrity, not authenticity. If an attacker controls the website, they can replace both the file and its checksum. For that, publishers sign releases with GPG or Sigstore, and app stores and package managers verify signatures automatically. On the command line, sha256sum on Linux, shasum -a 256 on macOS and Get-FileHash or certutil on Windows give the same values as this page.

Why you should never hash passwords with SHA-256 or MD5

General-purpose hashes are designed to be fast, and fast is exactly wrong for passwords. A modern GPU can compute billions of SHA-256 or MD5 hashes per second, so when a database of unsalted fast hashes leaks, most human-chosen passwords are recovered quickly with wordlists and rules. Identical passwords also produce identical hashes, revealing which users share a password.

Store passwords with a password-hashing function that is salted and deliberately slow and memory-hard: Argon2id is the current recommendation from OWASP, with scrypt, bcrypt or PBKDF2 where Argon2id is unavailable or FIPS validation is required. Libraries for every major language handle the salt and parameters for you. Our web app authentication guide covers sessions, tokens and passkeys, and the OWASP Top 10 lists cryptographic failures among the most common web vulnerabilities.

Hashing vs encryption vs encoding

Hashing is one-way: there is no key and no way to turn a digest back into the input, except by guessing inputs until one matches. Encryption is two-way: data is scrambled with a key and anyone with the right key can recover it. Encoding, such as Base64 or URL encoding, is not protection at all, just a reversible change of format.

Choose by purpose. To check that data has not changed, hash it. To keep data secret and read it later, encrypt it. To move binary data through a text-only channel, encode it with a tool such as the Base64 encoder.

Why is my hash different from another tool?

Almost always the input differs by an invisible character. echo "hello" | sha256sum hashes 'hello' plus a newline, which gives a completely different digest; use printf 'hello' or echo -n. Windows line endings (CRLF), a byte-order mark at the start of a file, trailing spaces, or a different text encoding such as UTF-16 all change the result. This page hashes text exactly as typed, encoded as UTF-8, and hashes files byte for byte.

Format matters too. Hex is case-insensitive, so the Uppercase hex option changes only how the digest looks, and the compare box ignores case. Some systems show digests in Base64 rather than hex, such as Subresource Integrity values like sha384-…, so the same hash can look entirely different.

How this hash generator works

SHA-1, SHA-256, SHA-384 and SHA-512 are computed with your browser's Web Crypto API, the same native code browsers use for TLS. Browsers do not provide MD5, so this page computes it with our own implementation of RFC 1321, tested against the standard test vectors. Files are read into memory in this tab and never uploaded, which is why there is a 200 MB limit and why the page is safe for confidential documents and builds.

Beyond download checksums, hashes identify content everywhere in modern software: Git commits, container image digests written as sha256:…, cache-busting file names such as app.3f9a1c.js, ETags for HTTP caching and file deduplication. For any of these, SHA-256 is the safe default. It is fast enough for almost every workload and is hardware-accelerated on many current processors, so there is rarely a reason to reach for MD5 or SHA-1 in new code.

Questions, answered

Something else on your mind? Ask a consultant and get a reply within one business day.

How do I get the SHA-256 hash of a string or file?

Type the text above, or switch to File and drop the file in. The SHA-256 digest appears immediately with the other algorithms, ready to copy.

Are my files uploaded?

No. Files are read into memory in this tab and hashed locally with the Web Crypto API. Nothing leaves your device, so it is safe for private documents and builds.

Can a hash be reversed or decrypted?

No. Hashing is one-way and there is no key. Short or common inputs can still be found by guessing and comparing, which is why password hashes need salts and slow algorithms.

What is the difference between MD5 and SHA-256?

MD5 produces a 128-bit digest and is broken: attackers can create collisions. SHA-256 produces 256 bits, has no practical attacks and is the modern default for checksums and signatures.

Is MD5 still safe to use?

Only for non-security jobs such as spotting accidental corruption or as a cache key. Practical MD5 collisions have existed since 2004 and SHA-1 collisions since 2017, so neither should protect signatures, certificates or passwords.

Should I use SHA-256 to store passwords?

No. SHA-256 is too fast, so leaked hashes can be guessed at billions per second. Use a slow, salted password-hashing function such as Argon2id, scrypt or bcrypt.

Why do I get a different hash than another tool?

The input usually differs: a trailing newline, Windows line endings, a byte-order mark or a different text encoding. This tool hashes text as UTF-8 exactly as typed, and files byte for byte.

How long is a SHA-256 hash?

256 bits, which is 32 bytes or 64 hexadecimal characters. SHA-512 is 128 hex characters, SHA-1 40 and MD5 32.

What is a checksum?

A short value computed from a file that changes if the file changes. Comparing your file's SHA-256 with the publisher's checksum confirms the download is complete and unmodified.

Why is SHA-3 not included?

This page relies on the browser's Web Crypto API, which provides the SHA-1 and SHA-2 family but not SHA-3. SHA-256 and SHA-512 remain secure and are what most checksums use.

More free tools.

All tools

Need tooling like this inside your product?

We build internal tools, developer platforms and APIs. Tell us what your team keeps doing by hand.