Hash Generator
Paste text or pick a file and instantly see its MD5, SHA-1, SHA-256, SHA-512 and SHA-3 hash. It also verifies the checksum of a downloaded file.
-
HMAC-MD5 broken legacy
The hash will appear here -
HMAC-SHA-1 broken legacy
The hash will appear here -
HMAC-SHA-256
The hash will appear here -
HMAC-SHA-512
The hash will appear here
What a hash is and what it is for
A hash is a short, fixed-length fingerprint of any data. A hash function such as SHA-256 calculates it, and the same input always produces the same result. Change a single letter, though, and the hash is completely different. That is why hashes are used to check that a download is not corrupted, to compare data without sending it, and to sign messages between applications.
How a hash behaves
The SHA-256 hash function turns any input into a fingerprint with a fixed length of 64 characters.
Change a single letter and the hash is completely different. 60 of the 64 characters changed.
The same input always gives the same hash. That is how you check a download: compare its hash with the published one.
It only works in one direction. You cannot directly calculate the original data from the hash.
How to create a hash
Add text or a file
Type or paste text into the field, or choose or drop a file on the page. The hash updates as you type.
Pick algorithms and a format
Turn on the algorithms you need. The result can be lowercase or uppercase hex, or Base64.
Copy or compare
Copy any hash with one click. Paste the expected hash into the compare field and the tool tells you whether it matches.
Which algorithm to choose
For checking files and for new projects, use SHA-256. MD5 and SHA-1 are broken, so only use them where another system requires them.
| Algorithm | Length | When to use it |
|---|---|---|
| MD5 | 128 bits, 32 characters | Only as a checksum against accidental corruption. A regular computer can create a collision in seconds. |
| SHA-1 | 160 bits, 40 characters | Older systems and Git. The first collision was published in 2017 and it is no longer used for signatures. |
| SHA-256 | 256 bits, 64 characters | Today's standard for file checksums, certificates, blockchain and HMAC signatures. |
| SHA-384 | 384 bits, 96 characters | Certificates and TLS with a higher security level. |
| SHA-512 | 512 bits, 128 characters | When you want a longer fingerprint and stronger collision resistance. |
| SHA3-256, SHA3-512 | 256 and 512 bits | The newer SHA-3 family with a different internal design. A fallback in case a weakness is ever found in SHA-2. |
How to verify the checksum of a download
Installers, disk images and firmware often come with a published SHA-256 checksum. If it matches the hash of your file, the download is complete and error-free. Always take the checksum from the author's official page.
-
On the page you downloaded the file from, find its SHA-256 checksum. It is usually next to the download link or in a
SHA256SUMSfile. - Switch the generator to File and choose the downloaded file.
- Paste the published checksum into Compare with a hash. A green message means it matches.
File hash on the command line
You get the same result without a browser. Replace file.iso with the name of your file.
- Windows (PowerShell)
Get-FileHash .\file.iso -Algorithm SHA256- Windows (Command Prompt)
certutil -hashfile file.iso SHA256- macOS
shasum -a 256 file.iso- Linux
sha256sum file.iso
HMAC: a hash with a secret key
HMAC combines a message with a secret key, so only someone who knows the key can calculate the right result. This is how GitHub and Shopify sign webhooks, for example. When debugging a webhook, turn on HMAC with a secret key, paste the request body exactly as it arrived and compare the result with the signature in the header. Some services sign more than the body: Stripe, for example, calculates the HMAC from the timestamp, a dot and the body, so check the documentation for exactly what a service signs.
Do not store passwords as a plain hash
MD5, SHA-1 and SHA-256 are not meant for storing passwords. They are designed to be fast, so an attacker can try billions of passwords per second and find common ones in ready-made tables. For passwords, use functions that are deliberately slow and add a random salt: Argon2id, bcrypt or scrypt. Most languages and frameworks offer them out of the box.
Related Tools
More tools for preparing, editing, and checking text.
FAQ
Can a hash be decrypted or turned back into text?
Is MD5 still secure?
Why do I get a different hash than in the terminal or another tool?
echo command adds a newline at the end, so use echo -n or printf in the terminal. Windows stores a line break as two characters (CR LF), while this field uses one (LF). A trailing space or the encoding can also make a difference: this tool converts text to UTF-8, while older Windows programs use other code pages, so words with accents produce a different hash. For files, encoding does not matter because they are hashed byte by byte.
Is my text or file uploaded to a server?
How large a file can I hash?
What is the difference between SHA-256 and SHA-512?
What is SHA-3 and should I use it?
Does uppercase or lowercase matter in a hash?
A1B2 and a1b2 are the same hash, and the compare field accepts both. Base64, however, is case-sensitive, so every character has to match. The input is case-sensitive too: "Hello" and "hello" produce completely different hashes.