Hash Generator
Every common digest of your text, computed on your device.
Runs entirely in your browser
Loading the tool…
A hash turns any input into a fixed-length fingerprint. The same input always gives the same digest, and changing one character changes the whole thing. That makes hashes useful for checking a download arrived intact, or for spotting whether two files differ.
MD5 and SHA-1 are here because checksums in the wild still use them, not because they are safe. Both are broken for collision resistance: an attacker can construct two different inputs with the same digest. Use SHA-256 or better for anything where an adversary might want a collision.
How to use it
- Type or paste the text you want to hash.
- All five digests appear immediately.
- Copy the one you need, or compare it against a published checksum.
Questions
Is hashing the same as encryption?
No, and the difference matters. Encryption is reversible with the key; hashing is one-way by design. There is no way to turn a digest back into the original text, and a site claiming to 'decrypt' a hash is really looking it up in a table of pre-computed common inputs.
Should I use MD5?
Not for security. MD5 collisions can be produced in seconds on a laptop, and SHA-1 fell in 2017. Both remain fine for non-adversarial integrity checks, like spotting accidental corruption, which is why they are still printed next to downloads.
Can I hash a file?
This tool hashes text you paste. For a file, use your operating system: shasum -a 256 file on macOS and Linux, or Get-FileHash file in PowerShell on Windows.
Is my text sent anywhere?
No. The digests are computed in WebAssembly inside this page, so you can disconnect from the network and it still works.
Can a hash be reversed?
Not by computation: the function throws away length and structure, and many inputs map to any given digest. But short or common inputs can simply be looked up, because someone has already hashed every word in the dictionary and every password in every breach. A hash of something guessable is not a secret.
Is MD5 or SHA-256 good enough for storing passwords?
No, and this is the most consequential thing on the page. Both are built to be fast, and fast is exactly wrong for passwords: a modern GPU tries billions of guesses a second. Use bcrypt, scrypt or Argon2, which are deliberately slow, memory-hungry and salted. A password database hashed with SHA-256 is a database of passwords.
What is a salt, and why does it matter?
A random value stored alongside each password and mixed in before hashing. Without one, identical passwords produce identical digests, so a single lookup table cracks every account at once and anyone can see which users share a password. A salt makes each hash a separate problem. It is not a secret and does not need to be.
Why does my checksum not match the one on the website?
Usually one of three things. The file downloaded incompletely, which is what the check is for. Or the published hash is of the archive and you hashed the extracted file. Or you are hashing text rather than bytes: this page hashes what you paste, encoded as UTF-8, and a trailing newline or Windows line endings change the digest completely.
Which one should I pick?
SHA-256 unless something tells you otherwise. Use MD5 or SHA-1 only to match a checksum somebody else published, never for anything an attacker would want to forge.
The five algorithms, and where they stand
| Algorithm | Digest | Hex characters | Status |
|---|---|---|---|
| MD5 | 128 bits | 32 | Broken. Collisions have been cheap since 2004 |
| SHA-1 | 160 bits | 40 | Broken. First real collision published in 2017 |
| SHA-256 | 256 bits | 64 | Current default for almost everything |
| SHA-384 | 384 bits | 96 | SHA-512 truncated, common in TLS suites |
| SHA-512 | 512 bits | 128 | Sound, and faster than SHA-256 on 64-bit hardware |
"Broken" is narrower than it sounds. It means an attacker can build two different inputs with the same digest, which destroys MD5 and SHA-1 for signatures and for anything an adversary can influence. It does not stop either from noticing that a download arrived corrupted, which is why they are still printed next to files.
The digest of nothing at all
Every hash function has a digest for the empty input, and these turn up constantly in logs and databases as the fingerprint of a file that was never written. Recognising them saves an afternoon:
| MD5 | d41d8cd98f00b204e9800998ecf8427e |
| SHA-1 | da39a3ee5e6b4b0d3255bfef95601890afd80709 |
| SHA-256 | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
Clear the box above and you will get exactly those back.
Your data stays on your device
Everything above runs inside your browser as WebAssembly compiled from Rust. Nothing you type is uploaded, logged or stored on a server. You can load this page once, go offline, and it still works.
This page makes no requests at all, to anywhere. That is not a promise in the copy: it is a Content-Security-Policy header your browser enforces, and connect-src on it is none. Open the network tab and watch nothing happen.