Hash Generator
Compute SHA-1, SHA-256, SHA-384, SHA-512, MD5 and CRC32 for text or files, all at once. Files are hashed locally whatever their size, and the result can be checked straight against a published checksum.
Verifying a download
- Copy the SHA-256 checksum published alongside the download.
- Switch to the File tab and drop your downloaded file in.
- Paste the published checksum into the compare box.
A match means your copy is byte-for-byte identical to whatever the checksum describes. That is only as good as the checksum's source: if both the file and the checksum came from the same compromised mirror, they will agree perfectly. Take the checksum from the project's own site over HTTPS, not from the download page you were redirected to.
Algorithm reference
| Algorithm | Output | Status |
|---|---|---|
| SHA-1 | 160 bits, 40 hex chars | Broken — legacy only |
| SHA-256 | 256 bits, 64 hex chars | Current standard |
| SHA-384 | 384 bits, 96 hex chars | Secure |
| SHA-512 | 512 bits, 128 hex chars | Secure, fast on 64-bit |
| MD5 | 128 bits, 32 hex chars | Broken — published checksums only |
| CRC32 | 32 bits, 8 hex chars | Error detection, never security |
Note the avalanche effect: change one character of the input and roughly half the output bits flip. Hashing "hello" and "hellp" gives digests that differ in 131 of 256 bits. There is no such thing as a hash that is "close" to another — it either matches exactly or tells you nothing.
Frequently asked questions
Should I use the MD5 output?
Only for the job it is still good at: checking a download against an MD5 checksum a project published. MD5 is cryptographically broken — two different files can be made to share a digest, and have been since 2004 — so a match proves the file is not corrupted, not that nobody altered it. The Web Crypto API omits MD5 for that reason, which is why this tool ships its own implementation. Where a publisher offers SHA-256 as well, use that instead.
What is a checksum used for?
Verifying that a file arrived intact. Software projects publish the SHA-256 of each download; you hash your copy and compare. If a single byte changed in transit the hash differs completely. Note what this does and does not establish: it proves your copy matches the checksum you were given, so it is only as trustworthy as the channel that checksum came through.
Can I get the original text back from a hash?
No. Hashing is one-way by design and the output is fixed-length regardless of input size, so information is necessarily discarded. What an attacker can do is hash billions of likely inputs and look for a match, which is why hashing passwords with a plain SHA function is inadequate — those need a slow, salted algorithm such as Argon2 or bcrypt.
Which SHA variant should I choose?
SHA-256 for essentially everything — it is the industry default, widely supported and has no known practical weakness. SHA-512 is not meaningfully more secure in practice but is faster on 64-bit hardware for large inputs. SHA-1 is broken and should only be used to check against legacy systems that still publish it.
Related tools
- Diagram & Flowchart MakerDraw flowcharts and diagrams, connect the boxes with arrows that route themselves, and let it arrange the whole thing. Exports SVG. Nothing is uploaded.
- Password GeneratorGenerate strong random passwords using your browser's cryptographic RNG, with a live strength estimate.
- HTML Entity EncoderEncode text for HTML or decode entities back — the five markup breakers, named Latin-1 and symbol sets, numeric references up to emoji. Decodes exactly once.