Skip to content
HNarzędzia
en
Categories

Hash generator - MD5, SHA-1, SHA-256 and SHA-512 online

Type text or drop a file to get all common hashes at once. Paste the checksum published by a vendor to verify that your download is intact - the file is hashed locally and never uploaded.

  • Free
  • No sign-up
  • Private
  • Runs locally
AlgorithmHash
MD5
SHA-1
SHA-256
SHA-384
SHA-512

MD5 and SHA-1 are not cryptographically secure - use them only for integrity checks, not for passwords or signatures.

How to generate a hash or verify a checksum

  1. 1.

    Choose the input

    Pick “Text” to hash a string (UTF-8) or “File” to hash any file from your disk.

  2. 2.

    Read the hashes

    MD5, SHA-1, SHA-256, SHA-384 and SHA-512 appear together. Switch between lowercase hex, uppercase HEX and Base64.

  3. 3.

    Verify a checksum

    Paste the hash from the vendor’s website into the compare field. The tool tells you which algorithm matches, or that none does.

What a hash function does

A cryptographic hash function turns data of any size into a fixed-length fingerprint. The same input always gives the same hash, while the smallest change - one letter, one byte - gives a completely different result (the avalanche effect). You cannot reconstruct the input from the hash.

AlgorithmLengthHash of “abc” (start)Security
MD5128 bits (32 hex chars)900150983cd24fb0…broken - integrity only
SHA-1160 bits (40)a9993e364706816a…broken - integrity only
SHA-256256 bits (64)ba7816bf8f01cfea…secure
SHA-384384 bits (96)-secure
SHA-512512 bits (128)ddaf35a193617aba…secure

Verifying a downloaded file

Linux distributions, ISO images, installers and firmware are often published with a SHA-256 checksum next to the download link. After downloading, compute the file hash and compare it with the published one: a match means the file was not corrupted in transit or swapped by an attacker. You can do the same from the command line:

  • Windows (PowerShell): Get-FileHash file.iso -Algorithm SHA256
  • macOS: shasum -a 256 file.iso
  • Linux: sha256sum file.iso

Here the file is read and hashed inside your browser with the Web Crypto API - nothing is uploaded, so this works for confidential documents too. Comparison ignores letter case and spaces, and accepts both hex and Base64.

Why you should not hash passwords with SHA-256

Fast hash functions - MD5, SHA-1 and even SHA-256 - are the wrong tool for storing passwords. A single graphics card can compute billions of them per second, which makes dictionary and brute-force attacks cheap. Passwords need deliberately slow, salted functions: Argon2id, bcrypt, scrypt or PBKDF2. MD5 is not even available in the browser Web Crypto API because of its weaknesses; this tool includes its own RFC 1321 implementation purely for checking legacy checksums.

If you need a strong password in the first place, use the password generator.

Which algorithm to use

Use caseAlgorithm
Verifying a download (ISO, installer)whatever the publisher used - usually SHA-256
Legacy checksums, file deduplicationMD5 or SHA-1 (integrity only)
Digital signatures, certificates, Git (SHA-256 repos)SHA-256
Larger security margin, fast on 64-bit CPUsSHA-384 or SHA-512
Storing passwordsnone of these - Argon2id or bcrypt

If your hash differs from one computed elsewhere, the cause is almost always the input, not the algorithm: a trailing newline, an extra space, Windows CRLF line endings or a different text encoding. This tool hashes the text exactly as typed, encoded as UTF-8.

Frequently asked questions

Can a hash be reversed to get the original text?

+
No. A hash function is one-way, it is not encryption. Short or common inputs such as weak passwords can still be guessed by comparing them with precomputed tables of hashes.

Why is my hash different from the one another tool gives?

+
Usually because of invisible differences in the input: a trailing newline, a space, CRLF instead of LF, or a different encoding. This tool hashes your text exactly as entered, in UTF-8.

Which algorithm should I choose?

+
For checksums and signatures use SHA-256 (or SHA-512). Use MD5 or SHA-1 only when the system you are comparing against requires it.

Can I hash large files?

+
Yes, though the whole file is loaded into browser memory. Files up to a few hundred MB work fine on a typical computer.

What is the difference between hex and Base64 output?

+
It is the same hash written differently. Hex uses 2 characters per byte (SHA-256 = 64 characters), Base64 about 1.33 (SHA-256 = 44 characters). Base64 is used, for example, in the HTML integrity attribute (SRI).

Is my file uploaded to a server?

+
No. The file is read and hashed locally in your browser using the Web Crypto API, so even confidential files are safe to check.

Updated: