Skip to content

Hash Generator

Paste text or pick a file and instantly see its MD5, SHA-1, SHA-256, SHA-512 and SHA-3 hash. It also verifies the checksum of a downloaded file.

Format

Algorithms
  • MD5 broken
    The hash will appear here
  • SHA-1 broken
    The hash will appear here
  • SHA-256
    The hash will appear here
  • SHA-512
    The hash will appear here
Text and files are never uploaded, the hash is calculated in your browser.

What a hash is and what it is for

A hash is a short, fixed-length fingerprint of any data. A hash function such as SHA-256 calculates it, and the same input always produces the same result. Change a single letter, though, and the hash is completely different. That is why hashes are used to check that a download is not corrupted, to compare data without sending it, and to sign messages between applications.

How a hash behaves

SHA-256 hash after a small change of the input The text Hello world and its SHA-256 hash. Changing one letter produces a completely different hash. The same input always gives the same hash, and the input cannot be calculated back from the hash. Input Hello world hello world SHA-256 Hash (SHA-256) changed characters: 60/64 6 4 e c 8 8 c a 0 0 b 2 6 8 e 5 b a 1 a 3 5 6 7 8 a 1 b 5 3 1 6 d 2 1 2 f 4 f 3 6 6 b 2 4 7 7 2 3 2 5 3 4 a 8 a e c a 3 7 f 3 c b 9 4 d 2 7 b 9 9 3 4 d 3 e 0 8 a 5 2 e 5 2 d 7 d a 7 d a b f a c 4 8 4 e f e 3 7 a 5 3 8 0 e e 9 0 8 8 f 7 a c e 2 e f c d e 9 Published hash 64ec88ca00b2…4a8aeca37f3c ✓ match No way back

The SHA-256 hash function turns any input into a fingerprint with a fixed length of 64 characters.

Change a single letter and the hash is completely different. 60 of the 64 characters changed.

The same input always gives the same hash. That is how you check a download: compare its hash with the published one.

It only works in one direction. You cannot directly calculate the original data from the hash.

How to create a hash

Add text or a file

Type or paste text into the field, or choose or drop a file on the page. The hash updates as you type.

Pick algorithms and a format

Turn on the algorithms you need. The result can be lowercase or uppercase hex, or Base64.

Copy or compare

Copy any hash with one click. Paste the expected hash into the compare field and the tool tells you whether it matches.

Which algorithm to choose

For checking files and for new projects, use SHA-256. MD5 and SHA-1 are broken, so only use them where another system requires them.

Algorithm Length When to use it
MD5 128 bits, 32 characters Only as a checksum against accidental corruption. A regular computer can create a collision in seconds.
SHA-1 160 bits, 40 characters Older systems and Git. The first collision was published in 2017 and it is no longer used for signatures.
SHA-256 256 bits, 64 characters Today's standard for file checksums, certificates, blockchain and HMAC signatures.
SHA-384 384 bits, 96 characters Certificates and TLS with a higher security level.
SHA-512 512 bits, 128 characters When you want a longer fingerprint and stronger collision resistance.
SHA3-256, SHA3-512 256 and 512 bits The newer SHA-3 family with a different internal design. A fallback in case a weakness is ever found in SHA-2.

How to verify the checksum of a download

Installers, disk images and firmware often come with a published SHA-256 checksum. If it matches the hash of your file, the download is complete and error-free. Always take the checksum from the author's official page.

  • On the page you downloaded the file from, find its SHA-256 checksum. It is usually next to the download link or in a SHA256SUMS file.
  • Switch the generator to File and choose the downloaded file.
  • Paste the published checksum into Compare with a hash. A green message means it matches.

File hash on the command line

You get the same result without a browser. Replace file.iso with the name of your file.

Windows (PowerShell)
Get-FileHash .\file.iso -Algorithm SHA256
Windows (Command Prompt)
certutil -hashfile file.iso SHA256
macOS
shasum -a 256 file.iso
Linux
sha256sum file.iso

HMAC: a hash with a secret key

HMAC combines a message with a secret key, so only someone who knows the key can calculate the right result. This is how GitHub and Shopify sign webhooks, for example. When debugging a webhook, turn on HMAC with a secret key, paste the request body exactly as it arrived and compare the result with the signature in the header. Some services sign more than the body: Stripe, for example, calculates the HMAC from the timestamp, a dot and the body, so check the documentation for exactly what a service signs.

Do not store passwords as a plain hash

MD5, SHA-1 and SHA-256 are not meant for storing passwords. They are designed to be fast, so an attacker can try billions of passwords per second and find common ones in ready-made tables. For passwords, use functions that are deliberately slow and add a random salt: Argon2id, bcrypt or scrypt. Most languages and frameworks offer them out of the box.

FAQ

Can a hash be decrypted or turned back into text?

No. A hash is not encryption and has no key to decrypt it. Short and common inputs, such as the word "password123", can still be guessed: an attacker hashes millions of known words and compares the results. Sites that promise to "decrypt MD5" are simply searching databases like that.

Is MD5 still secure?

Not for security. Two different files with the same MD5 hash can be created on a regular computer in seconds, so MD5 does not protect against deliberate changes. It still works as a checksum against accidental corruption in transfer, and some systems still require it.

Why do I get a different hash than in the terminal or another tool?

Usually because of invisible characters. The echo command adds a newline at the end, so use echo -n or printf in the terminal. Windows stores a line break as two characters (CR LF), while this field uses one (LF). A trailing space or the encoding can also make a difference: this tool converts text to UTF-8, while older Windows programs use other code pages, so words with accents produce a different hash. For files, encoding does not matter because they are hashed byte by byte.

Is my text or file uploaded to a server?

No. The hash is calculated right in your browser, and neither the text nor the file leaves your computer. You can safely hash confidential documents too.

How large a file can I hash?

The file is read in chunks, so it does not have to fit in memory, and even a disk image of several GB works. Speed depends on your computer and on how many algorithms are turned on. For large files, keep only the one you need.

What is the difference between SHA-256 and SHA-512?

Both belong to the SHA-2 family and both are secure today. SHA-512 gives a longer hash, 128 hex characters instead of 64. Which one is faster depends on the processor and the implementation, and in everyday use you will not notice a difference. Unless you have a specific reason, choose SHA-256, because most tools and services use it.

What is SHA-3 and should I use it?

SHA-3 is a newer standard from 2015 built on a completely different principle than SHA-2. It was not created because SHA-2 was broken, but as a fallback. Use it if the system you work with requires it. Otherwise use SHA-256, which is more widespread and offers the same security level as SHA3-256.

Does uppercase or lowercase matter in a hash?

For hex, no: A1B2 and a1b2 are the same hash, and the compare field accepts both. Base64, however, is case-sensitive, so every character has to match. The input is case-sensitive too: "Hello" and "hello" produce completely different hashes.

How is a hash different from encryption?

Encryption can be reversed: whoever has the key gets the original data back. A hash is one-way, and the original data cannot be rebuilt from it. Encryption protects content, while a hash shows whether content has changed.