A cryptographic hash function turns any input — a word, a document, a 4 GB disk image — into a short fixed-length fingerprint. Change a single bit and the fingerprint changes completely. That makes hashes ideal for checking that a download was not corrupted or tampered with, for detecting duplicate files, and as building blocks of signatures, password storage and blockchains. This generator computes all common digests at once, for text or for a file on your device.
How to use the hash generator
- Choose Text or A file. Text is hashed as UTF-8 exactly as typed; a file is read locally, never uploaded.
- Pick the algorithm to show in large type and the output style: lowercase hex, uppercase hex or Base64. The table below always lists all five algorithms.
- Optionally enter an HMAC secret key to compute keyed HMAC values instead of plain hashes.
- To verify a download, paste the publisher’s checksum into Expected hash. The tape reports a match and names the algorithm, or flags a mismatch.
How the algorithms compare
| Algorithm | Digest size | Hex characters | Status |
|---|---|---|---|
| MD5 | 128 bits | 32 | Broken; accidental-corruption checks only |
| SHA-1 | 160 bits | 40 | Collisions demonstrated; legacy only |
| SHA-256 | 256 bits | 64 | Current standard (FIPS 180-4) |
| SHA-384 | 384 bits | 96 | SHA-2 family, truncated SHA-512 |
| SHA-512 | 512 bits | 128 | SHA-2 family, fast on 64-bit CPUs |
The SHA-2 functions are specified by NIST in FIPS 180-4. They are computed here by the browser’s built-in Web Crypto API. MD5 is not offered by Web Crypto, so this page includes a small local implementation for legacy checksums. The length of a hex digest is a quick clue to which algorithm produced it: 64 hex characters almost always means SHA-256.
Worked example
Hash the sentence The quick brown fox jumps over the lazy dog (43 bytes, no trailing newline).
SHA-256: d7a8fbb307d7809469ca9abcb0082e4f8d5651e46d3cdb762d02d0bf37c9e592
MD5: 9e107d9d372bb6826bd81d3542a419d6
Now add a period at the end. The SHA-256 becomes ef537f25c895bfa782526529a9b63d97aa631564d5d789c2b765448c8635fb6c — one extra character, and every hex digit is unrelated to the first result. This is the avalanche effect.
With the HMAC key key, HMAC-SHA256 of the original sentence is f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8.
The empty string has a well-known SHA-256 too: e3b0c442…7852b855. If you see that value where you expected a file’s hash, the file was empty or was not read.
Verifying a download
- Find the checksum on the publisher’s official site — usually SHA-256, listed next to the download link or in a SHA256SUMS file.
- Choose A file, select the downloaded file and paste the published value into Expected hash.
- A match means the file is bit-for-bit identical to what the publisher hashed. A mismatch means a corrupted or incomplete download, the wrong file version, or tampering — download it again from the official source.
A checksum on the same page as the download protects against corruption but not against a compromised website; signed checksums (for example with PGP or code-signing certificates) protect against that too.
Hashes are not password storage
Fast hashes like SHA-256 can be computed billions of times per second on a GPU, so an unsalted password hash can be cracked by guessing. Password databases need a deliberately slow, salted key-derivation function: NIST SP 800-63B requires a salted, costly one-way function, and OWASP recommends Argon2id, scrypt or bcrypt. Use this tool for checksums, fingerprints and HMAC testing — not to prepare passwords for storage.
To encode the raw bytes of a digest in Base64 or back, use the Base64 encoder and decoder. For random secrets and keys, the password generator uses the same cryptographic random source.
Frequently asked questions
Can a hash be reversed to get the original text?
No. A cryptographic hash is a one-way function: there is no formula to recover the input. Short or common inputs such as dictionary words can still be found by guessing and comparing, which is why passwords need slow, salted algorithms rather than a plain SHA-256.
Is MD5 or SHA-1 still safe to use?
Not for security. Practical collision attacks exist for both — researchers produced two different PDF files with the same SHA-1 hash in 2017. They remain fine for spotting accidental corruption, such as checking a download against a published MD5 sum, but use SHA-256 or stronger for anything an attacker might target.
Why does my hash differ from another tool's?
Almost always the input differs: a trailing newline, Windows line endings (CR LF), extra spaces or a different text encoding. This tool hashes exactly what is in the box as UTF-8; command-line echo adds a newline unless you use echo -n.
What is HMAC?
A hash-based message authentication code (RFC 2104): the message is hashed together with a secret key in a specific two-pass construction. Only someone with the key can produce or check the value, which is why APIs and webhooks use HMAC-SHA256 to sign requests.
Is my file uploaded?
No. The browser reads the file into memory and hashes it locally with the Web Crypto API. Nothing leaves your device.