SHA-1 hash generator

SHA-1 (NIST FIPS 180, 1995) produces a 160-bit digest, 40 hex characters. Google and CWI published the first real collision ("SHAttered") in 2017, and browsers stopped trusting SHA-1 certificates. It survives in Git object IDs (with collision detection) and legacy systems.

Loading…

Where SHA-1 is used

  • Git commit and object IDs
  • Legacy HMAC-SHA1 APIs (still considered safe as an HMAC)
  • Verifying old checksums

Command line

sha1sum file.txt
shasum -a 1 file.txt     # macOS
echo -n "text" | sha1sum

In code

# Python
hashlib.sha1(b"text").hexdigest()

// Node.js
crypto.createHash('sha1').update('text').digest('hex')

Hashing is deterministic and one-way: the same bytes always give the same 160-bit value, and a one-character change scrambles it completely — try the avalanche demo.

Questions

How long is a SHA-1 hash?

160 bits, written as 40 hexadecimal characters (or 27 Base64 characters plus padding).

Is SHA-1 secure?

Deprecated for security. Collisions can be produced on purpose, so do not rely on it where an attacker controls input. It is fine for detecting accidental corruption.

Can I decrypt a SHA-1 hash?

No — hashing is one-way. Lookup sites only find inputs that are already in their tables of common strings.