Hash Generator

Generate MD5, SHA-1, SHA-256, SHA-384, and SHA-512 hashes from any text. Free, browser-based, no data sent to servers.

  • Runs in your browser
  • Your data never leaves your browser
  • Free · No Sign-Up
Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 from the current text. Editing does not calculate again. Use Ctrl/⌘+Enter to generate while focused in the tool. SHA uses the browser Web Crypto API; after an error, try Generate Hashes again.
Clear empties the input and all results and discards pending results. Ctrl/⌘+L does the same while focused in the tool. This tool does not save its input or results.
Enter text to hash as UTF-8 bytes. Spaces and line breaks count. Empty input is not hashed. An unpaired surrogate is replaced with U+FFFD when encoded.
Hashes Each Copy button copies that row’s complete lowercase hexadecimal value. If copying fails, select the value and copy it manually.

Your five hash values will appear here.

Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.

Which Hash Should I Use?

  • MD5: Legacy checksums and non-security file verification only.
  • SHA-1: Not safe for security uses, because collisions can be produced. Git still uses SHA-1 for object names by default.
  • SHA-256: The current standard for general cryptographic hashing, digital signatures, and TLS.
  • SHA-512: Larger output and security margin; whether it is faster or slower than SHA-256 depends on the CPU.

Never use MD5 or SHA-1 for password hashing. Use a slow hash function like bcrypt, scrypt, or Argon2 for passwords.

Check Your Result

Hashing the five characters hello gives:

AlgorithmOutput
MD55d41402abc4b2a76b9719d911017c592
SHA-1aaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d
SHA-2562cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
SHA-38459e1748777448c69de6b800d7a33bbfb9ff1b463e44354c3553bcdb9c666fa90125a3c79f90397bdf5f6a13de828684f
SHA-5129b71d224bd62f3785d96d46ad3ea3d73319bfbc2890caadae2dff72519673ca72323c3d99ba5c11d7c7acc6e14b8c5da0c4663475c2e5c3adef46f73bcdec043

If your terminal gives a different value, look for an invisible newline. echo "hello" | sha256sum hashes hello plus a line feed and prints 5891b5b522d5df086d0ff0b110fbd9d21bb4fc7163af34d08286a2e846f6be03; printf 'hello' | sha256sum matches the table. The same applies here: a trailing space or line break in the input box changes every hash.

Non-ASCII Text and Encodings

The two characters 你好 are six bytes in UTF-8 (e4 bd a0 e5 a5 bd), and the tool gives MD5 7eca689f0d3389d9dea66ae112e5cfd7 and SHA-256 670d9743542cae3ea7ebe36af56bd53648b0a1126162e78d81a32934a711302e. A program that stores the same text in GBK hashes four different bytes (c4 e3 ba c3) and gets MD5 b94ae3c6d892b29cf48d9bea819b27b9. When two systems disagree about the hash of text that looks identical, compare the bytes before suspecting the hash. Common causes:

  • a different encoding (GBK, Shift_JIS, UTF-16);
  • a byte order mark at the start of a file: hello saved as UTF-8 with BOM hashes to SHA-256 7489ebbcc2a00056ddaaaac190bce473e5c03696ea1bd8ed83cf59a174283862;
  • Windows line endings (\r\n) instead of \n;
  • characters that look the same but are different code points, such as a composed é and e plus a combining accent.

Why Git’s SHA-1 Is Different

git hash-object does not hash the file content alone. It hashes a header, the word blob, a space, the size in bytes and a NUL byte, followed by the content. For a file containing hello and a line feed, Git reports ce013625030ba8dba906f756967f9e9ca394464a, while the SHA-1 of the same six bytes is f572d396fae9206628714fb2ce00f72e94f2258f. This tool computes the second kind of value. Git repositories still use SHA-1 object names by default; SHA-256 repositories are an opt-in format.

Hashing Files

This page hashes text only. To hash a file without uploading it, use the File Hash Checker, or run one of these commands:

sha256sum archive.tar.gz                            # Linux
shasum -a 256 archive.tar.gz                        # macOS
certutil -hashfile archive.tar.gz SHA256            # Windows cmd
Get-FileHash archive.tar.gz -Algorithm SHA256       # PowerShell

Passwords Need a Slow Hash

MD5, SHA-1, and the SHA-2 family are designed to be fast, which lets an attacker test guesses quickly. Store passwords with Argon2id, scrypt, or bcrypt, as the OWASP Password Storage Cheat Sheet recommends.

Limits

  • Text only, encoded as UTF-8 before hashing. The same characters in another encoding (for example GBK or Shift_JIS) produce different hashes.
  • Empty input is not hashed. For reference, the SHA-256 of an empty string is e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855.
  • Output is lowercase hexadecimal only. There is no Base64 output, which some systems expect (for example the sha256-… values in Subresource Integrity).
  • No secret key. A hash of a message plus a password is not a message authentication code; use the HMAC Generator for signed webhooks and API requests.
  • SHA-3, BLAKE2 and CRC32 are not offered here. The File Hash Checker adds CRC32 for files.

FAQ

Is my input sent to any server?

No. MD5 is computed via a pure-JavaScript implementation. SHA variants use the browser's built-in Web Crypto API (SubtleCrypto). Nothing leaves your machine.

What is MD5 used for?

MD5 is a legacy checksum algorithm. It is NOT suitable for security-sensitive hashing. Use SHA-256 or stronger for integrity checks, and a slow password hash (Argon2id, scrypt, bcrypt) for passwords.

Can I hash files with this tool?

This tool hashes text (UTF-8 encoded). To hash a file, use the File Hash Checker tool.

What is the difference between SHA-256 and SHA-512?

SHA-256 produces a 256-bit (32-byte) digest; SHA-512 produces a 512-bit (64-byte) digest. SHA-512 provides a larger security margin; which one is faster depends on the CPU.