How to generate a hash or verify a checksum
- 1.
Choose the input
Pick “Text” to hash a string (UTF-8) or “File” to hash any file from your disk.
- 2.
Read the hashes
MD5, SHA-1, SHA-256, SHA-384 and SHA-512 appear together. Switch between lowercase hex, uppercase HEX and Base64.
- 3.
Verify a checksum
Paste the hash from the vendor’s website into the compare field. The tool tells you which algorithm matches, or that none does.
What a hash function does
A cryptographic hash function turns data of any size into a fixed-length fingerprint. The same input always gives the same hash, while the smallest change - one letter, one byte - gives a completely different result (the avalanche effect). You cannot reconstruct the input from the hash.
| Algorithm | Length | Hash of “abc” (start) | Security |
|---|---|---|---|
| MD5 | 128 bits (32 hex chars) | 900150983cd24fb0… | broken - integrity only |
| SHA-1 | 160 bits (40) | a9993e364706816a… | broken - integrity only |
| SHA-256 | 256 bits (64) | ba7816bf8f01cfea… | secure |
| SHA-384 | 384 bits (96) | - | secure |
| SHA-512 | 512 bits (128) | ddaf35a193617aba… | secure |
Verifying a downloaded file
Linux distributions, ISO images, installers and firmware are often published with a SHA-256 checksum next to the download link. After downloading, compute the file hash and compare it with the published one: a match means the file was not corrupted in transit or swapped by an attacker. You can do the same from the command line:
- Windows (PowerShell):
Get-FileHash file.iso -Algorithm SHA256 - macOS:
shasum -a 256 file.iso - Linux:
sha256sum file.iso
Here the file is read and hashed inside your browser with the Web Crypto API - nothing is uploaded, so this works for confidential documents too. Comparison ignores letter case and spaces, and accepts both hex and Base64.
Why you should not hash passwords with SHA-256
Fast hash functions - MD5, SHA-1 and even SHA-256 - are the wrong tool for storing passwords. A single graphics card can compute billions of them per second, which makes dictionary and brute-force attacks cheap. Passwords need deliberately slow, salted functions: Argon2id, bcrypt, scrypt or PBKDF2. MD5 is not even available in the browser Web Crypto API because of its weaknesses; this tool includes its own RFC 1321 implementation purely for checking legacy checksums.
If you need a strong password in the first place, use the password generator.
Which algorithm to use
| Use case | Algorithm |
|---|---|
| Verifying a download (ISO, installer) | whatever the publisher used - usually SHA-256 |
| Legacy checksums, file deduplication | MD5 or SHA-1 (integrity only) |
| Digital signatures, certificates, Git (SHA-256 repos) | SHA-256 |
| Larger security margin, fast on 64-bit CPUs | SHA-384 or SHA-512 |
| Storing passwords | none of these - Argon2id or bcrypt |
If your hash differs from one computed elsewhere, the cause is almost always the input, not the algorithm: a trailing newline, an extra space, Windows CRLF line endings or a different text encoding. This tool hashes the text exactly as typed, encoded as UTF-8.
Frequently asked questions
Can a hash be reversed to get the original text?
+
Why is my hash different from the one another tool gives?
+
Which algorithm should I choose?
+
Can I hash large files?
+
What is the difference between hex and Base64 output?
+
Is my file uploaded to a server?
+
Updated: