Hash Generator

Produce SHA-1, SHA-256, SHA-384 and SHA-512 hashes of any text.

Developer Tools Free, no sign-up Runs in your browser

Hash Generator tool

About the Hash Generator

A hash is a fixed-length fingerprint of a piece of data. Feed in a sentence or a whole book and you get back the same number of characters either way. Change a single letter of the input and the output changes completely, which is what makes hashes useful for checking that data arrived exactly as it was sent.

This tool computes MD5, SHA-1, SHA-256, SHA-384 and SHA-512 from the same input at once, each with its own copy button. The SHA family comes from the Web Crypto API built into your browser, the same implementation web applications use for security work, so the values match what any other correct implementation produces. MD5 is not part of Web Crypto, so it is implemented in the page itself, and it still produces the standard digest.

Hashing is one-way. There is no operation that turns a hash back into the original text, which is why hashes are used to verify rather than to store. It is worth knowing that SHA-1 is no longer considered safe against deliberate collision attacks and should not be used for signatures or certificates; it is included here because older systems still produce it and you may need to check a value.

How to use the Hash Generator

  1. Enter your textType or paste whatever you want to hash.
  2. Read the five hashesMD5, SHA-1, SHA-256, SHA-384 and SHA-512 are computed together as you type.
  3. Pick the one you needEach value has its own copy button.
  4. Compare if you are verifyingPaste a value you were given into the compare box to check it matches.

Features

  • MD5, SHA-1, SHA-256, SHA-384 and SHA-512 computed together
  • MD5 and SHA-1 clearly marked as legacy, for checksums rather than security
  • Uses the browser's own Web Crypto implementation
  • Correct UTF-8 handling, so accented text and emoji hash correctly
  • Live results as you type
  • A compare box that confirms whether a given hash matches
  • Copy any value in one click
  • Nothing is uploaded or stored

Who uses this tool

The hash generator is used by writers, developers, students, marketers and anyone else who needs the job done once without installing software. Common cases include:

  • Verifying that a downloaded value matches a published checksum
  • Generating a stable identifier from a string
  • Checking that two pieces of text are byte-for-byte identical
  • Producing a cache key from request parameters
  • Learning how hashing behaves when the input changes slightly

Frequently asked questions

Can a hash be reversed back into the original text?

No. Hashing is one-way by design. The only way to find an input that produces a given hash is to guess inputs and hash them, which is why short or common passwords can be cracked from a leaked hash while long random ones cannot.

Should I use MD5?

Only to check a value against an existing MD5 checksum. MD5 is thoroughly broken: collisions can be produced in seconds on a laptop, so it proves nothing against anyone who can choose the input. It remains useful for catching an accidentally corrupted download, and for matching the hashes that older systems and databases already store, which is why it is here and why it is labelled as legacy.

Should I use SHA-1?

Not for anything new. Practical collision attacks against SHA-1 have been demonstrated, so it must not be used for signatures, certificates or anything where an attacker could choose the input. It is provided for checking values produced by older systems.

Which one should I choose?

SHA-256 is the sensible default for general use. SHA-512 is not meaningfully more secure for most purposes but is faster on 64-bit hardware, which is why some systems prefer it.

Is hashing the right way to store passwords?

Not a plain hash. Passwords need a slow algorithm designed for the job, such as bcrypt, scrypt or Argon2, together with a unique salt for each user. A bare SHA-256 of a password is far too fast to compute and offers little protection once a database leaks.

Why does MD5 not come from the Web Crypto API?

Because the standard deliberately leaves it out. Web Crypto exposes SHA-1 and the SHA-2 family and nothing weaker, so a browser will refuse to compute MD5 for you. The MD5 here is a plain implementation of RFC 1321 written into the page, which runs in your browser like everything else on the site.

Is my text sent anywhere?

No. Both the Web Crypto API and the MD5 code run inside your browser, so the text and the resulting hashes never cross the network.

If the hash generator is not quite what you need, these other free tools solve closely related problems.

UUID Generator

Generate cryptographically random UUIDs in bulk, with format options.

Developer Tools Use tool

Password Generator

Generate strong random passwords with your own length and character rules.

Utility Tools Use tool

Base64 Encoder

Encode any text, including emoji and accents, to a Base64 string.

Encoding & Conversion Use tool

JWT Decoder

Decode a JWT to see its header, claims and expiry, without sending it anywhere.

Developer Tools Use tool

Text to Binary Converter

Convert text to binary or hex byte values, and convert them back to text.

Encoding & Conversion Use tool