SHA-256 Generator
Produce the 64-character SHA-256 digest of any string using your browser's own crypto.
Generate an MD5 hash of any text, instantly.
MD5 Generator produces the 128-bit MD5 digest of whatever you type or paste, shown as the familiar 32-character hexadecimal string. The result updates as you type and matches what any correct MD5 implementation produces for the same bytes.
A word about what MD5 is still good for. It is comprehensively broken as a security function: two different inputs that produce the same digest can be constructed in seconds on an ordinary laptop. That means MD5 proves nothing against anybody who can choose the input, and it must never be used for passwords, signatures, or verifying a download against a hostile party.
It remains genuinely useful for the jobs that do not involve an adversary. Checking that a file arrived intact, matching a value against an MD5 column an older system already stores, deduplicating records by content, and generating a stable cache key are all perfectly reasonable, and all of them are why this page exists.
The digest is calculated by a plain implementation of RFC 1321 written into the page. Browsers deliberately leave MD5 out of their built-in crypto, so it cannot come from there; it can, however, run entirely on your device, which is what happens here.
Everything runs inside your browser. Nothing you paste is uploaded, logged or stored, which matters when the input is a client list, an internal URL map or anything else you would not post publicly.
The md5 generator is used by writers, developers, students, marketers and anyone else who needs the job done once without installing software. Common cases include:
Not for anything an attacker can influence. Collisions can be produced in seconds, so MD5 must never be used for passwords, digital signatures or verifying a file against an untrusted source. It is fine for checking accidental corruption and for matching values older systems already store.
Not directly. Hashing is one-way. However, short or common inputs can be found by guessing, and vast precomputed tables of MD5 values exist, so an MD5 of a password offers almost no protection.
SHA-256 for general integrity and security work. For passwords specifically, neither MD5 nor SHA-256 is right: use a deliberately slow algorithm such as bcrypt, scrypt or Argon2 with a unique salt.
Because the standard deliberately excludes it. Web Crypto exposes SHA-1 and the SHA-2 family and nothing weaker. The MD5 here is implemented in the page itself.
Yes. The text is encoded as UTF-8 before hashing, which is what every other correct implementation does, so accented characters and emoji produce matching digests.
No. The calculation happens in your browser and the text never crosses the network.
If the md5 generator is not quite what you need, these other free tools solve closely related problems.
Produce the 64-character SHA-256 digest of any string using your browser's own crypto.
Generate cryptographic hashes of text, computed in your browser.
Generate strong random passwords with your own length and character rules.
Generate cryptographically random UUIDs in bulk, with format options.
Encode any text, including emoji and accents, to a Base64 string.