Skip to content

Hash Generator

Compute MD5, SHA-1, SHA-256 and SHA-512 digests of text, with a note where an algorithm is no longer fit for security use.

Hash Generator

Generate cryptographic hashes from text or a file.

What Hash Generator does

A hash function turns input of any length into a fixed-length fingerprint. The same input always gives the same digest, and any change to the input produces a completely different one.

Hashing is one-way: there is no operation that recovers the input from the digest. That makes it useful for verifying that data is unchanged, and useless as a way to store something you need back.

  • MD5, SHA-1, SHA-256 and SHA-512
  • Digest updates as you type
  • Warning shown when a broken algorithm is selected
  • Copy the hexadecimal digest

How to use Hash Generator

  1. 1

    Choose an algorithm

    SHA-256 is the reasonable default. MD5 and SHA-1 remain available for checking against legacy systems.

  2. 2

    Enter your text

    The digest is recomputed on every keystroke.

  3. 3

    Compare or copy

    Compare the digest against a published checksum, or copy it for your own records.

Example

One changed character changes the entire digest

Input

SHA-256 of "hello"
SHA-256 of "hellp"

Output

2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
0a1eb63a0a49b1c4e6b0b25c4b25e6a3b4ef7bd8b3cb6b4d5b9db8e6c9f3b0d2

This avalanche property is what makes a digest useful for detecting change: nothing about the digests suggests the inputs differed by one letter.

When to use it

Verifying a download

Compare the digest published by a project against the one computed from the file you received.

Detecting duplicates

Identical content produces identical digests, so hashes work as content fingerprints.

Checking a legacy integration

Some older systems still exchange MD5 checksums; you can reproduce them here to compare.

Limits and known behaviour

  • MD5 and SHA-1 are broken for security purposes. Practical collision attacks exist, so neither should be used for signatures or to prove that a file has not been tampered with by an adversary. They are still fine for detecting accidental corruption.
  • No hash on this page is suitable for storing passwords. Password storage requires a deliberately slow function such as bcrypt, scrypt or Argon2, with a per-user salt.
  • Hashing is not encryption; there is no key and no way to recover the input.
  • Short or predictable inputs offer no protection: an attacker with a dictionary can hash every candidate and compare.
  • Digests are computed over the exact bytes you provide, so a trailing newline or a different text encoding changes the result.

Privacy and data handling

Runs entirely in your browser

  • Hashing runs in the page. Your input is not transmitted anywhere.
  • Nothing is retained after the tab is closed.

Site-wide data handling, including analytics and advertising, is described in the privacy policy.

Frequently asked questions

Can I reverse a hash?

No. What lookup sites do is hash enormous lists of likely inputs and check for a match, which works for common passwords and short strings and not at all for anything unpredictable.

Is MD5 useless now?

It is useless against an adversary, because two different files can be constructed with the same MD5. It remains perfectly serviceable for spotting accidental corruption in a transfer, which is why it is still published alongside some downloads.

Why does my digest not match the one on the website?

Usually because the input differs in a way you cannot see: a trailing newline, different line endings, or the digest was computed over a file rather than over pasted text.