Hash generator

MD5, SHA-1, SHA-256, SHA-384 and SHA-512 of any text or file, all at once — plus HMAC signing and checksum comparison. Computed in your browser.

Loading…

Single-algorithm pages: MD5SHA-1SHA-256SHA-512

See the avalanche effect

Which algorithm, at a glance

AlgorithmOutputStatusUse it for
MD5128 bits / 32 hexBroken for securityFile checksums published next to downloads
SHA-1160 bits / 40 hexDeprecated for securityGit commit and object IDs
SHA-256256 bits / 64 hexSecureDownload checksums (sha256sum)
SHA-512512 bits / 128 hexSecureLinux password hashes ($6$ crypt) — as the core of a slow KDF, not alone

Verifying a download

Projects publish a SHA-256 next to their downloads. Switch to File, choose the file, and paste the published checksum into "Compare". On the command line the same check is sha256sum file.iso (Linux), shasum -a 256 file.iso (macOS) or Get-FileHash file.iso (PowerShell).

Checking a webhook signature

Tick HMAC, paste your signing secret as the key and the raw request body as the text. The HMAC-SHA256 output should equal the hex signature in the request header (for GitHub, X-Hub-Signature-256 without the sha256= prefix). The body must be byte-for-byte what was sent — re-serialised JSON won't match.

Questions

Is my text or file uploaded to compute the hash?

No. SHA hashes use your browser's built-in Web Crypto API and MD5 runs in JavaScript on the page. Files are read locally with the File API.

Can a hash be reversed or decrypted?

No. A hash is a one-way function, not encryption. "MD5 decrypt" sites only look up precomputed hashes of common strings — which is exactly why unsalted fast hashes are unsafe for passwords.

Which hash should I use?

SHA-256 for checksums, signatures and HMAC. MD5 and SHA-1 only for compatibility with existing systems. For passwords, use a slow password hash such as Argon2id, scrypt or bcrypt — never a plain SHA or MD5.

What is HMAC?

A hash-based message authentication code (RFC 2104): a hash of your message mixed with a secret key. Services such as GitHub, Stripe and Slack sign webhooks with HMAC-SHA256 so you can check a request really came from them.

Why does my hash differ from another tool?

Usually invisible input differences: a trailing newline (echo adds one — use echo -n), Windows line endings, or a different text encoding. This tool hashes the exact UTF-8 bytes of what is in the box.