Hash Generator

Works offlineNothing is uploadedFree, no sign-up
With a key, every row below becomes a keyed HMAC — what webhooks and API signatures use.
—
—
—
—
—
—

Hashing uses the Web Crypto API on your device. Files are never uploaded.

Compute SHA-1, SHA-256, SHA-384, SHA-512, MD5 and CRC32 for text or files, all at once. Files are hashed locally whatever their size, and the result can be checked straight against a published checksum.

Verifying a download

  1. Copy the SHA-256 checksum published alongside the download.
  2. Switch to the File tab and drop your downloaded file in.
  3. Paste the published checksum into the compare box.

A match means your copy is byte-for-byte identical to whatever the checksum describes. That is only as good as the checksum's source: if both the file and the checksum came from the same compromised mirror, they will agree perfectly. Take the checksum from the project's own site over HTTPS, not from the download page you were redirected to.

Algorithm reference

AlgorithmOutputStatus
SHA-1160 bits, 40 hex charsBroken — legacy only
SHA-256256 bits, 64 hex charsCurrent standard
SHA-384384 bits, 96 hex charsSecure
SHA-512512 bits, 128 hex charsSecure, fast on 64-bit
MD5128 bits, 32 hex charsBroken — published checksums only
CRC3232 bits, 8 hex charsError detection, never security

Note the avalanche effect: change one character of the input and roughly half the output bits flip. Hashing "hello" and "hellp" gives digests that differ in 131 of 256 bits. There is no such thing as a hash that is "close" to another — it either matches exactly or tells you nothing.

Frequently asked questions

Should I use the MD5 output?

Only for the job it is still good at: checking a download against an MD5 checksum a project published. MD5 is cryptographically broken — two different files can be made to share a digest, and have been since 2004 — so a match proves the file is not corrupted, not that nobody altered it. The Web Crypto API omits MD5 for that reason, which is why this tool ships its own implementation. Where a publisher offers SHA-256 as well, use that instead.

What is a checksum used for?

Verifying that a file arrived intact. Software projects publish the SHA-256 of each download; you hash your copy and compare. If a single byte changed in transit the hash differs completely. Note what this does and does not establish: it proves your copy matches the checksum you were given, so it is only as trustworthy as the channel that checksum came through.

Can I get the original text back from a hash?

No. Hashing is one-way by design and the output is fixed-length regardless of input size, so information is necessarily discarded. What an attacker can do is hash billions of likely inputs and look for a match, which is why hashing passwords with a plain SHA function is inadequate — those need a slow, salted algorithm such as Argon2 or bcrypt.

Which SHA variant should I choose?

SHA-256 for essentially everything — it is the industry default, widely supported and has no known practical weakness. SHA-512 is not meaningfully more secure in practice but is faster on 64-bit hardware for large inputs. SHA-1 is broken and should only be used to check against legacy systems that still publish it.

Related tools