MD5 Generator
Produce the standard 32-character MD5 digest of any string in your browser.
Generate a SHA-256 hash of any text, instantly.
SHA-256 Generator produces the 256-bit SHA-2 digest of whatever you paste, shown as 64 hexadecimal characters. It is the default choice for integrity checking and the hash underneath a great deal of modern infrastructure, from TLS certificates to Bitcoin.
Unlike MD5 and SHA-1, SHA-256 has no known practical collision attack. Nobody has produced two different inputs with the same SHA-256 digest, and on current understanding nobody is going to. That is what makes it suitable where an adversary might choose the input: signatures, certificate fingerprints, content addressing and download verification.
The calculation uses the Web Crypto API built into your browser, which is the same implementation web applications use for security work. That means the values here match any other correct implementation exactly, and that the work happens on your own device.
One common misuse is worth naming. SHA-256 is not a password hashing function. It is designed to be fast, and fast is exactly wrong for passwords, because it lets an attacker with a leaked database try billions of guesses per second. Passwords need bcrypt, scrypt or Argon2 with a per-user salt.
Everything runs inside your browser. Nothing you paste is uploaded, logged or stored, which matters when the input is a client list, an internal URL map or anything else you would not post publicly.
The sha-256 generator is used by writers, developers, students, marketers and anyone else who needs the job done once without installing software. Common cases include:
Yes, for the jobs hashes are meant for. There is no known practical way to find two inputs with the same digest, which is why it underpins TLS certificates, software signing and a great deal else.
No. It is one-way. The only approach is guessing inputs and hashing them, which is why a SHA-256 of a long random string is safe and a SHA-256 of 'password123' is not.
No. It is far too fast. A leaked database of SHA-256 password hashes can be attacked at billions of guesses per second. Use bcrypt, scrypt or Argon2 with a unique salt for each user.
SHA-2 is the family; SHA-256 is the 256-bit member of it, alongside SHA-384 and SHA-512. SHA-256 is the usual default.
Almost always a text encoding difference, or a trailing newline. This page encodes as UTF-8 with no added characters, which is the standard behaviour.
No. The Web Crypto API runs inside your browser.
If the sha-256 generator is not quite what you need, these other free tools solve closely related problems.
Produce the standard 32-character MD5 digest of any string in your browser.
Generate cryptographic hashes of text, computed in your browser.
Decode a JWT to see its header, claims and expiry, without sending it anywhere.
Generate strong random passwords with your own length and character rules.
Generate cryptographically random UUIDs in bulk, with format options.