๐ Hash Generator
Compute MD5, SHA-1, SHA-256, SHA-384, and SHA-512 hashes from text. Useful for checking file integrity, testing password hashing behavior, or learning how API request signing works.
How to use
- Enter the text you want to hash into the input box.
- MD5, SHA-1, SHA-256, SHA-384, and SHA-512 values are computed and shown in real time.
- Toggle uppercase if needed, and click "Copy" to copy a value.
How the calculation works
A hash function computes a fixed-length value from data of any length. The same input always gives the same output, while changing a single character produces a completely different value, and recovering the input from the output is infeasible. This tool computes SHA-1, SHA-256, SHA-384 and SHA-512 with the browser's standard Web Crypto API. The Web Crypto API does not provide MD5, so MD5 is computed by an implementation following RFC 1321. Input text is converted to UTF-8 bytes first. Practical collision attacks โ deliberately producing two inputs with the same hash โ have been demonstrated against MD5 (128-bit) and SHA-1 (160-bit), so they should not be used for security purposes such as digital signatures. They are still used for things like detecting corrupted files.
Worked example
Hashes of "abc" MD5: 900150983cd24fb0d6963f7d28e17f72 SHA-256: ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad Changing just the last character to "abd" gives a SHA-256 starting a52d159f262b2c6dโฆ, bearing no resemblance to the hash of "abc". This is known as the avalanche effect.
Things to be aware of
- Do not use MD5 or SHA-1 for security purposes.
- Do not store passwords with a plain hash function; use a dedicated scheme with salting and a work factor, such as bcrypt or Argon2.
- Line breaks and trailing spaces change the hash. Check copied text for stray characters at either end.
- To hash a file itself, use the file hash checker.
FAQ
I've heard MD5 isn't safe anymore โ is that true?
Yes. MD5 and SHA-1 are vulnerable to collision attacks and aren't recommended for security purposes like password storage. Use them only for non-security checks, and prefer SHA-256 or stronger for anything security-related.
Is my input text sent to a server?
No โ everything is computed in your browser, so your input never leaves your device.
Can it hash a file?
This tool hashes text you type or paste in. To hash a file's contents, you'd need its content in a form you can paste as text.
Can I use this for storing passwords?
This tool is meant for testing and learning. For real password storage, use a purpose-built algorithm like bcrypt or Argon2 with a proper salt.
Does the same text always give the same hash?
Yes โ a hash function is deterministic, so identical input always produces identical output. Changing even one character produces a very different result.