Hash Generator
Processed Client SideGenerate MD5, SHA-1, SHA-256, and SHA-512 hashes for any input text. SHA hashes use the Web Crypto API.
Bookmark this tool now — skip the search next time you need it.
About Hash Generator
This tool runs entirely in your browser. Whatever you paste is processed on your own device and is never uploaded, logged, or sent to any server.
Produce MD5, SHA-1, SHA-256, and SHA-512 hashes of any text, all four at once, from a single input. A hash is a one-way fingerprint: the same input always produces the same digest, and there is no way to reverse a digest back into the original. That makes hashes the standard way to verify that a file or message has not been altered, to compare two values without storing either, and to build checksums. The SHA family here is computed with the browser native Web Crypto implementation. MD5 and SHA-1 are included because you will still meet them in legacy systems and checksum files, and both are clearly labelled as deprecated.
Key features
- Four algorithms computed simultaneously from one input: MD5, SHA-1, SHA-256, and SHA-512
- SHA hashes computed with the browser native Web Crypto API
- MD5 and SHA-1 are explicitly badged as deprecated, so nobody picks them by accident
- Uppercase toggle to match the format used by checksum files and legacy systems
- Copy any single digest, or copy all four at once as a labelled list
- Correct UTF-8 handling, so hashing non-ASCII text gives the same digest as your backend would
- Runs entirely in your browser — the text you hash is never transmitted
How to use it
- Enter or paste the text you want to hash.
- Click Generate — all four digests are produced together.
- Toggle UPPERCASE if you are comparing against a checksum written in uppercase hex.
- Copy an individual hash with its row button, or use Copy all.
Tips & common mistakes
- Do not hash passwords with any of these. Fast hashes are exactly what makes brute-forcing cheap — use bcrypt, scrypt, or Argon2, which are deliberately slow and salted.
- MD5 and SHA-1 are both broken for security purposes: practical collision attacks exist for both. They are fine for a non-adversarial checksum, and unfit for signatures or integrity against a motivated attacker.
- SHA-256 is the sensible default for new work. SHA-512 is not meaningfully more secure for most uses, though it is often faster on 64-bit hardware.
- Hashing is not encryption — there is no key and no way back. If you need to recover the original value later, you want encryption, not a hash.
- A digest changes completely when one bit of input changes, so comparing two hashes tells you whether inputs are identical but never how similar they are.
- Whitespace counts. A trailing newline is why a hash computed here can differ from one computed over a file with the same visible content.
- To verify a downloaded file against a published checksum, use your operating system tool (shasum or certutil) on the file itself — this tool hashes text you paste, not file contents.
- Need to convert that hex digest to decimal or binary? Use the Number Base Converter.
- Need a random unique identifier rather than a hash of specific content? Generate one with the UUID Generator.
- Need a keyed hash for verifying message authenticity rather than a plain digest? Use the HMAC Generator.