Hash Generator
Generate MD5, SHA-1, SHA-256, SHA-384, and SHA-512 hashes from any text. Free, browser-based, no data sent to servers.
- Runs in your browser
- Your data never leaves your browser
- Free · No Sign-Up
Scan with WeChat to share this tool
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.
Which Hash Should I Use?
- MD5: Legacy checksums and non-security file verification only.
- SHA-1: Not safe for security uses, because collisions can be produced. Git still uses SHA-1 for object names by default.
- SHA-256: The current standard for general cryptographic hashing, digital signatures, and TLS.
- SHA-512: Larger output and security margin; whether it is faster or slower than SHA-256 depends on the CPU.
Never use MD5 or SHA-1 for password hashing. Use a slow hash function like bcrypt, scrypt, or Argon2 for passwords.
Check Your Result
Hashing the five characters hello gives:
| Algorithm | Output |
|---|---|
| MD5 | 5d41402abc4b2a76b9719d911017c592 |
| SHA-1 | aaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d |
| SHA-256 | 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824 |
| SHA-384 | 59e1748777448c69de6b800d7a33bbfb9ff1b463e44354c3553bcdb9c666fa90125a3c79f90397bdf5f6a13de828684f |
| SHA-512 | 9b71d224bd62f3785d96d46ad3ea3d73319bfbc2890caadae2dff72519673ca72323c3d99ba5c11d7c7acc6e14b8c5da0c4663475c2e5c3adef46f73bcdec043 |
If your terminal gives a different value, look for an invisible newline. echo "hello" | sha256sum hashes hello plus a line feed and prints 5891b5b522d5df086d0ff0b110fbd9d21bb4fc7163af34d08286a2e846f6be03; printf 'hello' | sha256sum matches the table. The same applies here: a trailing space or line break in the input box changes every hash.
Non-ASCII Text and Encodings
The two characters 你好 are six bytes in UTF-8 (e4 bd a0 e5 a5 bd), and the tool gives MD5 7eca689f0d3389d9dea66ae112e5cfd7 and SHA-256 670d9743542cae3ea7ebe36af56bd53648b0a1126162e78d81a32934a711302e. A program that stores the same text in GBK hashes four different bytes (c4 e3 ba c3) and gets MD5 b94ae3c6d892b29cf48d9bea819b27b9. When two systems disagree about the hash of text that looks identical, compare the bytes before suspecting the hash. Common causes:
- a different encoding (GBK, Shift_JIS, UTF-16);
- a byte order mark at the start of a file:
hellosaved as UTF-8 with BOM hashes to SHA-2567489ebbcc2a00056ddaaaac190bce473e5c03696ea1bd8ed83cf59a174283862; - Windows line endings (
\r\n) instead of\n; - characters that look the same but are different code points, such as a composed
éandeplus a combining accent.
Why Git’s SHA-1 Is Different
git hash-object does not hash the file content alone. It hashes a header, the word blob, a space, the size in bytes and a NUL byte, followed by the content. For a file containing hello and a line feed, Git reports ce013625030ba8dba906f756967f9e9ca394464a, while the SHA-1 of the same six bytes is f572d396fae9206628714fb2ce00f72e94f2258f. This tool computes the second kind of value. Git repositories still use SHA-1 object names by default; SHA-256 repositories are an opt-in format.
Hashing Files
This page hashes text only. To hash a file without uploading it, use the File Hash Checker, or run one of these commands:
sha256sum archive.tar.gz # Linux
shasum -a 256 archive.tar.gz # macOS
certutil -hashfile archive.tar.gz SHA256 # Windows cmd
Get-FileHash archive.tar.gz -Algorithm SHA256 # PowerShell
Passwords Need a Slow Hash
MD5, SHA-1, and the SHA-2 family are designed to be fast, which lets an attacker test guesses quickly. Store passwords with Argon2id, scrypt, or bcrypt, as the OWASP Password Storage Cheat Sheet recommends.
Limits
- Text only, encoded as UTF-8 before hashing. The same characters in another encoding (for example GBK or Shift_JIS) produce different hashes.
- Empty input is not hashed. For reference, the SHA-256 of an empty string is
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. - Output is lowercase hexadecimal only. There is no Base64 output, which some systems expect (for example the
sha256-…values in Subresource Integrity). - No secret key. A hash of a message plus a password is not a message authentication code; use the HMAC Generator for signed webhooks and API requests.
- SHA-3, BLAKE2 and CRC32 are not offered here. The File Hash Checker adds CRC32 for files.
FAQ
Is my input sent to any server?
No. MD5 is computed via a pure-JavaScript implementation. SHA variants use the browser's built-in Web Crypto API (SubtleCrypto). Nothing leaves your machine.
What is MD5 used for?
MD5 is a legacy checksum algorithm. It is NOT suitable for security-sensitive hashing. Use SHA-256 or stronger for integrity checks, and a slow password hash (Argon2id, scrypt, bcrypt) for passwords.
Can I hash files with this tool?
This tool hashes text (UTF-8 encoded). To hash a file, use the File Hash Checker tool.
What is the difference between SHA-256 and SHA-512?
SHA-256 produces a 256-bit (32-byte) digest; SHA-512 produces a 512-bit (64-byte) digest. SHA-512 provides a larger security margin; which one is faster depends on the CPU.