Hash Generator & Crypto Tools
Hash text and files with MD5, SHA-1, SHA-2, SHA-3 and HMAC — computed in your browser.
- Runs in your browser
- No upload required
- Free, no signup
Every digest is computed at once, so you can compare algorithms on the same input without switching anything.
MD5 and SHA-1 are not safe for security work. Both are reversible in the ways that matter: collisions can be produced deliberately, so a matching MD5 or SHA-1 digest does not prove the data is unchanged. Use them only for non-adversarial checksums or to interoperate with an older system.
HMAC mixes a secret key into the hash, so the result proves both that the message is unchanged and that whoever produced the digest knew the key.
Your key stays in this page. The key is held only in the input field and is passed to the browser’s Web Crypto API. It is never sent to a server, never written to storage, and never logged.
Compute a checksum for a file on your own machine. Handy for confirming a download arrived intact.
The file is read by your browser and never uploaded. That is why the limit is 100 MB — the whole file has to fit in memory here to be hashed.
SHA-3 is not offered for files. Browsers do not provide it natively and the implementation used here would be noticeably slow on a large file. Use SHA-256 or SHA-512 for checksums; both are computed natively and far faster.
Check whether two digests are the same. Case, spacing and any sha256: style prefix are ignored, so a hash copied from different tools still compares correctly.
To check whether a piece of text matches a hash, use the Hash text tab first and copy the digest it produces.
Your data is processed locally in your browser and is not uploaded to our server.
A hash function turns any input into a fixed-length digest. The same input always produces the same digest, a different input produces an unrelated one, and the original cannot be recovered from the result. That combination is what makes hashing useful for checking that data has not changed.
Every digest on this page is computed by your browser — SHA-1 and the SHA-2 family through the built-in Web Crypto API, MD5 and SHA-3 through implementations shipped with the page. Hashing a file reads it from your disk without uploading it, which matters when the file is a private key or a customer export.
How to use this tool
- Hash text: type or paste into the first tab. All nine supported algorithms are computed at once, so you can compare them directly. Press Copy next to any digest.
- HMAC: enter a secret key and a message, choose the hash algorithm, and generate. The key never leaves the page.
- File hash: choose a file or drop it onto the picker. It is read locally and hashed with MD5, SHA-1, SHA-256, SHA-384 and SHA-512.
- Compare: paste two digests to check whether they are identical. Case, spacing and any algorithm prefix are ignored, so hashes copied from different tools still line up.
MD5 Hash Generator
MD5 produces a 128-bit digest and is fast. For example, md5("abc") is 900150983cd24fb0d6963f7d28e17f72. It is still everywhere — in legacy checksum files, in ETags, in cache keys, in older database schemas.
It is also thoroughly broken for security purposes. Practical collision attacks have been public since 2004, and chosen-prefix collisions let an attacker produce two different files with the same MD5 digest. Two files matching does not mean they are the same file. Use MD5 to detect accidental corruption; do not use it to prove integrity against someone who wants to fool you.
MD5 is not encryption. It is one-way, and a correct-looking MD5 match proves nothing against a deliberate attacker.
SHA-1 Hash Generator
SHA-1 gives a 160-bit digest, and for a long time it was the default choice for certificates and version control. That has changed. A collision attack producing two different PDFs with the same SHA-1 digest was demonstrated in 2017, and chosen-prefix attacks are now cheap enough to be practical.
Most browsers and certificate authorities no longer accept SHA-1 signatures, and Git has moved to SHA-256. It remains useful for verifying the checksum of a download against a value published by someone you trust, and for reading older systems, but it should not be chosen for anything new.
SHA-256 Hash Generator
SHA-256 is the workhorse of the SHA-2 family and the sensible default. It produces a 256-bit digest; sha256("abc") is ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad. No collision has ever been found, and the design is the same one that protects TLS, code signing and blockchain systems.
It is fast enough for files and for everyday use, and it is what you should reach for when a tool, an API or a document asks for "the hash" without being more specific.
SHA-512 Hash Generator
SHA-512 produces a 512-bit digest using 64-bit words instead of 32-bit ones. On 64-bit hardware that makes it comparable in speed to SHA-256 despite the extra rounds, and it offers a wider security margin.
Where it is the better choice: when you are building a key-derivation scheme, when you want maximum resistance for a long-lived signature, or when a specification simply names it. For an ordinary file checksum the extra characters buy very little.
SHA-3 Hash Generator
SHA-3 is a different design from SHA-2, built on the Keccak sponge construction rather than the Merkle–Damgård structure. It is not a replacement for SHA-2 and it is not stronger in everyday terms — it exists so that a catastrophic break in SHA-2 would not leave the world with only one family of hash functions.
This page offers SHA3-224, SHA3-256, SHA3-384 and SHA3-512. Because browsers do not provide SHA-3 natively, the implementation runs in JavaScript, so it is offered for text rather than for large files. The implementation is checked against the published FIPS 202 test vectors.
HMAC Generator
HMAC is a hash with a secret key mixed in, which turns a plain integrity check into an authenticated one. Anyone can compute sha256(message) and anyone can change the message and recompute it. Only someone holding the key can produce a valid HMAC, so a match proves the message came from someone with the key.
It is the mechanism behind signed webhooks — Stripe, GitHub and Slack all sign their payloads with HMAC — and behind API request signing. HMAC-SHA256 is the common default; HMAC-SHA1 still appears in older protocols such as TOTP, where it is used differently and the SHA-1 weaknesses do not apply in the same way.
An HMAC digest is only as secret as its key. Treat the key as a credential, not as part of the message.
File Hash Generator
Hashing a file is how you check that a download arrived intact or that two copies of a large asset are byte-for-byte identical. The file is read by your browser and never uploaded, so it works for documents and archives you would not want to send to a server.
The whole file has to be held in memory to be hashed, which is why there is a size limit. MD5 is included because many publishers still ship MD5 checksums, and MD5 is genuinely fine for detecting accidental transfer corruption, which is the job it is usually doing there.
Hash Comparison
Comparing digests by eye is a poor idea: two 64-character strings that differ in one character look identical at a glance. Paste both into the comparison tab and it reports whether they match after normalising case, whitespace and any algorithm prefix such as sha256:.
When they differ, the length is worth checking first. A 32-character mismatch against a 64-character value is a sure sign the two were produced by different algorithms, which is a much more common mistake than a genuine change in the underlying data.
Frequently asked questions
What is a hash?
A hash function takes any input and produces a fixed-length value called a digest. It is deterministic, so the same input always gives the same digest; it is one-way, so the input cannot be recovered from the digest; and it is sensitive, so a single changed character produces a completely different result. Those properties let you check that data has not changed without storing the data itself.
What is SHA-256?
SHA-256 is a hash function from the SHA-2 family, published by NIST, producing a 256-bit digest written as 64 hexadecimal characters. For instance, sha256("abc") is ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad. It is the default choice for checksums, signatures and certificates, and no collision has ever been found in it.
Is SHA-256 encryption?
No — and the distinction matters. Encryption is reversible with the right key; hashing is not reversible at all. You cannot decrypt a SHA-256 digest, and no key exists that would let you. If you need to recover the original data later, hashing is the wrong tool. Hashing is for proving something has not changed, not for hiding it.
What is the difference between MD5 and SHA-256?
MD5 is faster and produces a 128-bit digest; SHA-256 produces 256 bits and is designed to be collision-resistant. The practical difference is that deliberate collisions in MD5 are easy to produce and in SHA-256 they are not. MD5 is fine for spotting accidental corruption and unsafe for proving integrity to someone who might want to deceive you. When in doubt, use SHA-256.
What is HMAC?
HMAC is a construction that combines a hash function with a secret key, producing a digest that only someone holding the key could have generated. A plain hash proves the data has not changed accidentally; an HMAC proves it was produced by someone who knows the secret. That is why webhooks and API requests are signed with HMAC — it authenticates the sender as well as the message.