Hash Generator

Every common digest of your text, computed on your device.

Runs entirely in your browser

Loading the tool…

A hash turns any input into a fixed-length fingerprint. The same input always gives the same digest, and changing one character changes the whole thing. That makes hashes useful for checking a download arrived intact, or for spotting whether two files differ.

MD5 and SHA-1 are here because checksums in the wild still use them, not because they are safe. Both are broken for collision resistance: an attacker can construct two different inputs with the same digest. Use SHA-256 or better for anything where an adversary might want a collision.

How to use it

  1. Type or paste the text you want to hash.
  2. All five digests appear immediately.
  3. Copy the one you need, or compare it against a published checksum.

Questions

Is hashing the same as encryption?

No, and the difference matters. Encryption is reversible with the key; hashing is one-way by design. There is no way to turn a digest back into the original text, and a site claiming to 'decrypt' a hash is really looking it up in a table of pre-computed common inputs.

Should I use MD5?

Not for security. MD5 collisions can be produced in seconds on a laptop, and SHA-1 fell in 2017. Both remain fine for non-adversarial integrity checks, like spotting accidental corruption, which is why they are still printed next to downloads.

Can I hash a file?

This tool hashes text you paste. For a file, use your operating system: shasum -a 256 file on macOS and Linux, or Get-FileHash file in PowerShell on Windows.

Is my text sent anywhere?

No. The digests are computed in WebAssembly inside this page, so you can disconnect from the network and it still works.

Can a hash be reversed?

Not by computation: the function throws away length and structure, and many inputs map to any given digest. But short or common inputs can simply be looked up, because someone has already hashed every word in the dictionary and every password in every breach. A hash of something guessable is not a secret.

Is MD5 or SHA-256 good enough for storing passwords?

No, and this is the most consequential thing on the page. Both are built to be fast, and fast is exactly wrong for passwords: a modern GPU tries billions of guesses a second. Use bcrypt, scrypt or Argon2, which are deliberately slow, memory-hungry and salted. A password database hashed with SHA-256 is a database of passwords.

What is a salt, and why does it matter?

A random value stored alongside each password and mixed in before hashing. Without one, identical passwords produce identical digests, so a single lookup table cracks every account at once and anyone can see which users share a password. A salt makes each hash a separate problem. It is not a secret and does not need to be.

Why does my checksum not match the one on the website?

Usually one of three things. The file downloaded incompletely, which is what the check is for. Or the published hash is of the archive and you hashed the extracted file. Or you are hashing text rather than bytes: this page hashes what you paste, encoded as UTF-8, and a trailing newline or Windows line endings change the digest completely.

Which one should I pick?

SHA-256 unless something tells you otherwise. Use MD5 or SHA-1 only to match a checksum somebody else published, never for anything an attacker would want to forge.

The five algorithms, and where they stand

AlgorithmDigestHex charactersStatus
MD5128 bits32Broken. Collisions have been cheap since 2004
SHA-1160 bits40Broken. First real collision published in 2017
SHA-256256 bits64Current default for almost everything
SHA-384384 bits96SHA-512 truncated, common in TLS suites
SHA-512512 bits128Sound, and faster than SHA-256 on 64-bit hardware

"Broken" is narrower than it sounds. It means an attacker can build two different inputs with the same digest, which destroys MD5 and SHA-1 for signatures and for anything an adversary can influence. It does not stop either from noticing that a download arrived corrupted, which is why they are still printed next to files.

The digest of nothing at all

Every hash function has a digest for the empty input, and these turn up constantly in logs and databases as the fingerprint of a file that was never written. Recognising them saves an afternoon:

MD5d41d8cd98f00b204e9800998ecf8427e
SHA-1da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA-256e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

Clear the box above and you will get exactly those back.

Your data stays on your device

Everything above runs inside your browser as WebAssembly compiled from Rust. Nothing you type is uploaded, logged or stored on a server. You can load this page once, go offline, and it still works.

This page makes no requests at all, to anywhere. That is not a promise in the copy: it is a Content-Security-Policy header your browser enforces, and connect-src on it is none. Open the network tab and watch nothing happen.