Skip to main content

Hash Generator

Generate SHA-1, SHA-256, SHA-384 and SHA-512 hashes from text, all at once, in your browser. Uses the Web Crypto API, and nothing you type is uploaded.

Produce SHA-1, SHA-256, SHA-384 and SHA-512 digests of a piece of text, computed by the browser's Web Crypto implementation. All four are generated at once so you can copy whichever the system you are working with expects.

Hash Generator
SHA-1160 bit
—
SHA-256256 bit
—
SHA-384384 bit
—
SHA-512512 bit
—

// Hash Generator: Features

Four algorithms, computed together

SHA-256 is the default choice for almost everything today and is what you want unless something specifies otherwise. SHA-384 and SHA-512 produce longer digests and are used where a larger output is required, often in high-security or standards-driven contexts. SHA-1 is included because a great deal of existing infrastructure still emits it, most visibly Git commit identifiers, but it is broken for any purpose that depends on collision resistance and should not be chosen for new work.

Hashing is not encryption and not encoding

A hash is one-way: there is no operation that recovers the input from the digest. That is the opposite of encoding such as Base64, which anyone can reverse, and of encryption, which the key holder can reverse. The practical consequence is that a hash is useful for verifying that something has not changed and useless for storing something you need to read back.

Do not use these to store passwords

This is the most important caveat on the page. SHA-256 is designed to be fast, and speed is exactly the wrong property for password storage: a modern graphics card computes billions of SHA-256 hashes per second, so a stolen database of SHA-256 password hashes falls quickly to a dictionary attack. Password storage needs a deliberately slow algorithm with a per-user salt: bcrypt, scrypt or Argon2. Use these digests for integrity, not for credentials.

Where hashes earn their keep

Verifying that a downloaded file matches the checksum the publisher advertised. Detecting whether a piece of content has changed without storing the content itself. Building a cache key or a deduplication key from a payload. Producing the digest that goes into an HMAC or a signature. Git object identifiers. In each case the value is that a small fixed-size string stands in for something larger and changes completely if anything about the input changes.

Hashing is not anonymisation

Hashing uses the Web Crypto API in your browser, so the text is never transmitted, stored or logged. Internal identifiers, tokens and personal data can all be hashed here. Note that hashing something does not make it private if the input space is small: a hash of an email address or a phone number is trivially reversed by hashing candidates until one matches, which is why those are not considered anonymised.

// Hash Generator: FAQ

Which algorithms are supported?

SHA-1, SHA-256, SHA-384 and SHA-512, all computed at once from the same input so you can copy whichever one you need. These are the digest algorithms the Web Crypto API exposes.

Why is MD5 not included?

Because the Web Crypto API deliberately does not provide it. MD5 is comprehensively broken: collisions can be produced in seconds on ordinary hardware, so it offers no integrity guarantee against anyone acting deliberately. Where you still meet it, treat it as a checksum against accidental corruption and nothing more.

Can I use SHA-256 to store passwords?

No. Its speed, which is a virtue everywhere else, makes it unsuitable: an attacker with a stolen database can try billions of candidates per second. Use bcrypt, scrypt or Argon2, which are deliberately slow and salted per user. This is one of the most common and most damaging security mistakes.

Is SHA-1 still safe to use?

Not for anything relying on collision resistance. Practical collisions have been demonstrated, which is why certificate authorities abandoned it and why Git is migrating away from it. It remains present in a lot of existing infrastructure, so the tool generates it for compatibility, but it should not be chosen for new work.

Can a hash be reversed?

Not by computation, but often by guessing. If the input is drawn from a small or predictable set, such as an email address, a phone number or a common password, an attacker simply hashes candidates until one matches. That is why hashing alone does not anonymise personal data, and why salts exist.

Why does the same text give a different hash elsewhere?

Usually a difference in the bytes being hashed rather than in the algorithm. A trailing newline, a different character encoding, or a difference in line endings between Windows and Unix all change the input and therefore the digest completely. Check for invisible whitespace first.

Can I hash a file?

This tool hashes text. For verifying a downloaded file, your operating system provides the tool: shasum or sha256sum on macOS and Linux, and Get-FileHash in PowerShell on Windows. Those read the file as bytes, which is what a published checksum refers to.

What is a salt and why does it matter?

A salt is a random value combined with the input before hashing, stored alongside the result. It ensures that two users with the same password have different hashes, which defeats precomputed rainbow tables and forces an attacker to attack each entry separately. Password hashing algorithms handle salting for you; plain SHA-256 does not.

Is my input sent anywhere?

No. Hashing happens in your browser through the Web Crypto API, and the text is never transmitted, stored or logged. Closing the tab discards it.

Does the hash change if I add a single character?

Completely. A one-bit change in the input produces an output that shares no discernible relationship with the original, which is the avalanche property these algorithms are designed for. It is what makes a digest useful for detecting that something has changed.

// How to Use Hash Generator

  1. Paste the string to hash

    Put the text into the input box. Hashes are computed as you type, and all four algorithms update together from the same input.

  2. Pick the digest you need

    SHA-256 is the right default for new work. Choose SHA-384 or SHA-512 if a specification calls for a longer digest, and SHA-1 only when an existing system requires it.

  3. Copy the digest

    Copy the digest with the button beside it. If you are comparing against a published checksum, check for trailing whitespace in your input first, since it changes the result entirely.

Category Security