SHA-256 hash generator

SHA-256 is part of the SHA-2 family (NIST FIPS 180-4). It outputs 256 bits — 64 hex characters — and has no known practical attacks. It is the default choice for checksums, signatures, HMAC and content addressing.

Loading…

Where SHA-256 is used

  • Download checksums (sha256sum)
  • HMAC-SHA256 webhook signatures (Stripe, GitHub, Slack)
  • Bitcoin block hashing, Subresource Integrity, TLS certificates

Command line

sha256sum file.txt
shasum -a 256 file.txt   # macOS
Get-FileHash file.txt    # PowerShell (SHA-256 by default)
echo -n "text" | sha256sum

In code

# Python
hashlib.sha256(b"text").hexdigest()

// Node.js
crypto.createHash('sha256').update('text').digest('hex')

// Browser
const buf = await crypto.subtle.digest('SHA-256', new TextEncoder().encode('text'))
[...new Uint8Array(buf)].map(b => b.toString(16).padStart(2, '0')).join('')

Hashing is deterministic and one-way: the same bytes always give the same 256-bit value, and a one-character change scrambles it completely — try the avalanche demo.

Questions

How long is a SHA-256 hash?

256 bits, written as 64 hexadecimal characters (or 43 Base64 characters plus padding).

Is SHA-256 secure?

Secure. There are no known practical collision or preimage attacks. For passwords, still use a slow password hash (Argon2id, scrypt, bcrypt) rather than a single fast hash.

Can I decrypt a SHA-256 hash?

No — hashing is one-way. Lookup sites only find inputs that are already in their tables of common strings.