Hash generator (MD5, SHA-256 and more)

Generate a hash in your browser: your text and secret key are never uploaded, there is no limit on the length, and you can choose MD5, SHA-1, SHA-256, SHA-384 or SHA-512 as hex or Base64.

Algorithm
Output

How it works

  1. Paste your code

    Paste the code in the left box or open a file. No code to hand? Click Example.

  2. Instant result

    The result appears as you type. If there is an error, you see the line and character.

  3. Copy or download

    Copy the result with one click or save it as a file for your editor or project.

What is a hash?

A hash function turns any text into a fingerprint of fixed length. The same text always gives the same hash, but change one character and the hash is completely different. You can't turn a hash back into the text. Hashes are used to check that a download or message hasn't changed, or to compare data without storing it.

Every space and line break counts: "hello" and "hello " give different hashes. The text is hashed as UTF-8, just like sha256sum or PHP's hash().

Which algorithm?

  • SHA-256 is the standard for checksums, APIs and blockchains.
  • SHA-384 and SHA-512 are longer members of the same family.
  • MD5 and SHA-1 are still fine for spotting a corrupted file, but they are no longer safe against deliberate forgery. Don't use them for passwords or signatures.

Passwords should never be stored with a plain hash anyway, but with a slow function such as bcrypt or Argon2.

HMAC with a key

With HMAC, a secret key is mixed into the hash. Only someone who knows the key can produce the same code; that is how webhooks from payment providers prove a message really came from them. Hash each line separately gives one hash per line, handy for a list of e-mail addresses or IDs.

Checking a download

Many sites publish a SHA-256 checksum next to a download. To compare, hash the file on your own computer (sha256sum file.zip on Linux, shasum -a 256 file.zip on macOS, Get-FileHash file.zip in PowerShell) and compare it with the published value. This page hashes text, not files, so use it for strings: API keys, IDs, test data or the content of a small file that you paste.

Verifying a webhook signature

Providers such as payment services sign their webhooks with HMAC-SHA256: they hash the message body with a shared secret. To test your code, paste the exact body, enter the secret as the key and compare the result with the header they sent. Even one extra space or a different line ending changes the hash, so use the raw body.

A hash is not a way to store passwords

A fast hash such as SHA-256 can be guessed at billions of attempts per second. Passwords belong in a slow, salted function such as bcrypt, scrypt or Argon2. Use the hash generator for checksums and signatures instead.

See also: JWT decoder · Base64 encode.

Frequently asked questions

Which algorithm should I use for a checksum?

SHA-256 is the usual choice. MD5 and SHA-1 still detect accidental corruption, but they are not safe against deliberate tampering.

Why is my hash different from another tool's?

Hashes depend on every byte: a space, a line ending or a different encoding changes them. This tool hashes your text as UTF-8.

Can I get the original text back from a hash?

No. A hash is one way. People who seem to reverse hashes only look them up in tables of common values.

Is my text or key uploaded?

No. The hash is calculated in your browser, and nothing is sent.