Toolkit
All tools
Developer integrity utility · Free

Hash Generator

Produce MD5, SHA-1, SHA-256, SHA-384, and SHA-512 digests from text or a file, sign messages with HMAC, and check a download against its published checksum.

Hashed with Web Crypto in this browser
Source

What are you hashing?

Every algorithm runs at once over the UTF-8 bytes of your text, so you can compare digests side by side.

Output

Digest encoding

Hex is what checksum files and most command-line tools print. Base64 is common in HTTP headers, and base64url drops padding for use in URLs and JWTs.

Verification

Compare a checksum

Paste a published checksum to check it against every digest at once, in any of the three encodings.

Input

Text to hash

43 characters · 43 bytes UTF-8

Digests

Every algorithm, one pass

hex
MD5 · 128 bitLegacy

–

Checksums and legacy compatibility only: collisions are practical.

SHA-1 · 160 bitLegacy

–

Git object ids and legacy systems: collisions are demonstrated.

SHA-256 · 256 bit

–

The default choice for integrity, signatures, and file checksums.

SHA-384 · 384 bit

–

SHA-512 truncated to 384 bits, common in TLS suites.

SHA-512 · 512 bit

–

Widest digest here; faster than SHA-256 on 64-bit hardware.

Web Crypto and a local MD5 · nothing uploaded · nothing stored

How it works

A fixed-length fingerprint of any input.

A hash turns any amount of data into a fixed-width digest. Change one byte and the digest changes completely, which is what makes it useful for detecting corruption and tampering.

  1. 01

    Choose text, a file, or HMAC

    Type text to hash it as UTF-8, drop a file to checksum it locally, or switch to HMAC to sign a message with a secret key.

  2. 02

    Pick the encoding

    Read each digest as hex for checksum files and command-line comparison, or as Base64 and base64url for headers, tokens, and URLs.

  3. 03

    Copy or verify

    Copy any digest, or paste a published checksum and let the tool tell you which algorithm it matches.

Built for verification

Text, files, and keyed signatures in one workspace.

Five algorithms at once

MD5, SHA-1, SHA-256, SHA-384, and SHA-512 are computed together, so you never have to guess which one a project publishes.

Local file checksums

Verify a downloaded installer, archive, or ISO up to 512 MB without uploading it. The bytes are read into the tab and discarded.

Automatic checksum matching

Paste an expected value and every digest is compared for you, in all three encodings, with whitespace and colons ignored.

HMAC signatures

Sign a message with a secret key using SHA-1, SHA-256, SHA-384, or SHA-512, the same construction webhook providers use.

Honest security labelling

MD5 and SHA-1 are marked as legacy because practical collisions exist. They stay available for checksums and older systems.

Nothing leaves the browser

SHA hashing and HMAC use the Web Crypto API and MD5 runs in local JavaScript. No text, file, or secret key is ever transmitted.

Hashing questions

Algorithm choice, collisions, passwords, and privacy.

Which hash should I use?+

Use SHA-256 unless something specific requires otherwise; it is the modern default for integrity checks and signatures. SHA-512 is a fine alternative and is often faster on 64-bit hardware. Reach for MD5 or SHA-1 only when an existing system publishes them.

Why are MD5 and SHA-1 marked as legacy?+

Practical collision attacks exist for both, meaning an attacker can construct two different inputs with the same digest. That breaks them for signatures and tamper detection, though they remain useful for detecting accidental corruption and for compatibility with older tooling.

Can I use this to hash passwords?+

No. A raw hash is far too fast, which is exactly what makes password cracking cheap. Passwords need a slow, salted algorithm such as bcrypt, scrypt, or Argon2, applied on your server.

Is my file uploaded anywhere?+

No. The file is read into your browser tab's memory, hashed with the Web Crypto API or the local MD5 implementation, and never sent to a server. Closing the tab discards it.

How big a file can I checksum?+

The limit here is 512 MB, which keeps the tab responsive. Very large files are read entirely into memory, so a low-memory device may struggle well before that ceiling.

What is the difference between a hash and an HMAC?+

A hash depends only on the message, so anyone can recompute it. An HMAC also mixes in a secret key, so only someone holding that key can produce or verify the signature. That is why webhook providers use HMAC to prove a request came from them.

Why does the same text produce a different digest elsewhere?+

Almost always an encoding difference. This tool hashes the exact UTF-8 bytes of what you type. A trailing newline, different line endings, or a different character encoding will change the digest completely.

More focused tools, ready when you are.

Explore the growing collection for calculations, documents, writing, and everyday work.

Browse all tools