Linux password hashes ($6$ crypt) — as the core of a slow KDF, not alone
Verifying a download
Projects publish a SHA-256 next to their downloads. Switch to File, choose the file, and paste the published checksum into "Compare". On the command line the same check is sha256sum file.iso (Linux), shasum -a 256 file.iso (macOS) or Get-FileHash file.iso (PowerShell).
Checking a webhook signature
Tick HMAC, paste your signing secret as the key and the raw request body as the text. The HMAC-SHA256 output should equal the hex signature in the request header (for GitHub, X-Hub-Signature-256 without the sha256= prefix). The body must be byte-for-byte what was sent — re-serialised JSON won't match.
Questions
Is my text or file uploaded to compute the hash?
No. SHA hashes use your browser's built-in Web Crypto API and MD5 runs in JavaScript on the page. Files are read locally with the File API.
Can a hash be reversed or decrypted?
No. A hash is a one-way function, not encryption. "MD5 decrypt" sites only look up precomputed hashes of common strings — which is exactly why unsalted fast hashes are unsafe for passwords.
Which hash should I use?
SHA-256 for checksums, signatures and HMAC. MD5 and SHA-1 only for compatibility with existing systems. For passwords, use a slow password hash such as Argon2id, scrypt or bcrypt — never a plain SHA or MD5.
What is HMAC?
A hash-based message authentication code (RFC 2104): a hash of your message mixed with a secret key. Services such as GitHub, Stripe and Slack sign webhooks with HMAC-SHA256 so you can check a request really came from them.
Why does my hash differ from another tool?
Usually invisible input differences: a trailing newline (echo adds one — use echo -n), Windows line endings, or a different text encoding. This tool hashes the exact UTF-8 bytes of what is in the box.