Hash Generator (SHA-256, SHA-1, SHA-512)

Compute SHA-256, SHA-384, SHA-512, SHA-1 and MD5 digests of text or a local file, as hex or Base64, with optional HMAC and checksum verification.

Hash
Hashed exactly as typed, encoded as UTF-8. Spaces and line breaks count: one extra newline changes every digest.
With a key, the tool computes HMAC (RFC 2104), the keyed hash used to sign API requests and webhooks.

Algorithm
SHA-256
Input
43 bytes of text
Digest size
256 bits
Mode
plain hash
SHA-256 · hex d7a8fbb307d7809469ca9abcb0082e4f8d5651e46d3cdb762d02d0bf37c9e592 64 hex characters
Every algorithm for the same input
AlgorithmDigestBits
MD5broken — checksums only 9e107d9d372bb6826bd81d3542a419d6 128
SHA-1collisions found — legacy use 2fd4e1c67a2d28fced849ee1bb76e7391b93eb12 160
SHA-256SHA-2, the usual default d7a8fbb307d7809469ca9abcb0082e4f8d5651e46d3cdb762d02d0bf37c9e592 256
SHA-384SHA-2 ca737f1014a48f4c0b6dd43cb177b0afd9e5169367544c494011e3317dbf9a509cb1e5dc1e85a941bbee3d7f2afbc9b1 384
SHA-512SHA-2 07e547d9586f6a73f73fbac0435ed76951218fb7d0c8d788a309d785436bbb642e93a252a954f23912547d1e8a3b5ed6e1bfd7097821233fa0538f3db854fee6 512

A cryptographic hash function turns any input — a word, a document, a 4 GB disk image — into a short fixed-length fingerprint. Change a single bit and the fingerprint changes completely. That makes hashes ideal for checking that a download was not corrupted or tampered with, for detecting duplicate files, and as building blocks of signatures, password storage and blockchains. This generator computes all common digests at once, for text or for a file on your device.

How to use the hash generator

  1. Choose Text or A file. Text is hashed as UTF-8 exactly as typed; a file is read locally, never uploaded.
  2. Pick the algorithm to show in large type and the output style: lowercase hex, uppercase hex or Base64. The table below always lists all five algorithms.
  3. Optionally enter an HMAC secret key to compute keyed HMAC values instead of plain hashes.
  4. To verify a download, paste the publisher’s checksum into Expected hash. The tape reports a match and names the algorithm, or flags a mismatch.

How the algorithms compare

Algorithm Digest size Hex characters Status
MD5 128 bits 32 Broken; accidental-corruption checks only
SHA-1 160 bits 40 Collisions demonstrated; legacy only
SHA-256 256 bits 64 Current standard (FIPS 180-4)
SHA-384 384 bits 96 SHA-2 family, truncated SHA-512
SHA-512 512 bits 128 SHA-2 family, fast on 64-bit CPUs

The SHA-2 functions are specified by NIST in FIPS 180-4. They are computed here by the browser’s built-in Web Crypto API. MD5 is not offered by Web Crypto, so this page includes a small local implementation for legacy checksums. The length of a hex digest is a quick clue to which algorithm produced it: 64 hex characters almost always means SHA-256.

Worked example

Hash the sentence The quick brown fox jumps over the lazy dog (43 bytes, no trailing newline).

SHA-256: d7a8fbb307d7809469ca9abcb0082e4f8d5651e46d3cdb762d02d0bf37c9e592

MD5: 9e107d9d372bb6826bd81d3542a419d6

Now add a period at the end. The SHA-256 becomes ef537f25c895bfa782526529a9b63d97aa631564d5d789c2b765448c8635fb6c — one extra character, and every hex digit is unrelated to the first result. This is the avalanche effect.

With the HMAC key key, HMAC-SHA256 of the original sentence is f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8.

The empty string has a well-known SHA-256 too: e3b0c442…7852b855. If you see that value where you expected a file’s hash, the file was empty or was not read.

Verifying a download

  1. Find the checksum on the publisher’s official site — usually SHA-256, listed next to the download link or in a SHA256SUMS file.
  2. Choose A file, select the downloaded file and paste the published value into Expected hash.
  3. A match means the file is bit-for-bit identical to what the publisher hashed. A mismatch means a corrupted or incomplete download, the wrong file version, or tampering — download it again from the official source.

A checksum on the same page as the download protects against corruption but not against a compromised website; signed checksums (for example with PGP or code-signing certificates) protect against that too.

Hashes are not password storage

Fast hashes like SHA-256 can be computed billions of times per second on a GPU, so an unsalted password hash can be cracked by guessing. Password databases need a deliberately slow, salted key-derivation function: NIST SP 800-63B requires a salted, costly one-way function, and OWASP recommends Argon2id, scrypt or bcrypt. Use this tool for checksums, fingerprints and HMAC testing — not to prepare passwords for storage.

To encode the raw bytes of a digest in Base64 or back, use the Base64 encoder and decoder. For random secrets and keys, the password generator uses the same cryptographic random source.

Frequently asked questions

Can a hash be reversed to get the original text?

No. A cryptographic hash is a one-way function: there is no formula to recover the input. Short or common inputs such as dictionary words can still be found by guessing and comparing, which is why passwords need slow, salted algorithms rather than a plain SHA-256.

Is MD5 or SHA-1 still safe to use?

Not for security. Practical collision attacks exist for both — researchers produced two different PDF files with the same SHA-1 hash in 2017. They remain fine for spotting accidental corruption, such as checking a download against a published MD5 sum, but use SHA-256 or stronger for anything an attacker might target.

Why does my hash differ from another tool's?

Almost always the input differs: a trailing newline, Windows line endings (CR LF), extra spaces or a different text encoding. This tool hashes exactly what is in the box as UTF-8; command-line echo adds a newline unless you use echo -n.

What is HMAC?

A hash-based message authentication code (RFC 2104): the message is hashed together with a secret key in a specific two-pass construction. Only someone with the key can produce or check the value, which is why APIs and webhooks use HMAC-SHA256 to sign requests.

Is my file uploaded?

No. The browser reads the file into memory and hashes it locally with the Web Crypto API. Nothing leaves your device.

Last reviewed October 2026 by the CalcFluent editorial team. How we check our calculators.