/

Hash Generator

Processed Client Side

Generate MD5, SHA-1, SHA-256, and SHA-512 hashes for any input text. SHA hashes use the Web Crypto API.

Input · 1 lines · 0 chars
1 lines · 0 chars
Length: 0Lines: 1Size: 0 BytesCursor: 1:1
Hashes
Enter text and click Generate.
MD5128 bitsDeprecated
—
SHA-1160 bitsDeprecated
—
SHA-256256 bits
—
SHA-512512 bits
—

Bookmark this tool now — skip the search next time you need it.

About Hash Generator

This tool runs entirely in your browser. Whatever you paste is processed on your own device and is never uploaded, logged, or sent to any server.

Produce MD5, SHA-1, SHA-256, and SHA-512 hashes of any text, all four at once, from a single input. A hash is a one-way fingerprint: the same input always produces the same digest, and there is no way to reverse a digest back into the original. That makes hashes the standard way to verify that a file or message has not been altered, to compare two values without storing either, and to build checksums. The SHA family here is computed with the browser native Web Crypto implementation. MD5 and SHA-1 are included because you will still meet them in legacy systems and checksum files, and both are clearly labelled as deprecated.

Key features

  • Four algorithms computed simultaneously from one input: MD5, SHA-1, SHA-256, and SHA-512
  • SHA hashes computed with the browser native Web Crypto API
  • MD5 and SHA-1 are explicitly badged as deprecated, so nobody picks them by accident
  • Uppercase toggle to match the format used by checksum files and legacy systems
  • Copy any single digest, or copy all four at once as a labelled list
  • Correct UTF-8 handling, so hashing non-ASCII text gives the same digest as your backend would
  • Runs entirely in your browser — the text you hash is never transmitted

How to use it

  1. Enter or paste the text you want to hash.
  2. Click Generate — all four digests are produced together.
  3. Toggle UPPERCASE if you are comparing against a checksum written in uppercase hex.
  4. Copy an individual hash with its row button, or use Copy all.

Tips & common mistakes

  • Do not hash passwords with any of these. Fast hashes are exactly what makes brute-forcing cheap — use bcrypt, scrypt, or Argon2, which are deliberately slow and salted.
  • MD5 and SHA-1 are both broken for security purposes: practical collision attacks exist for both. They are fine for a non-adversarial checksum, and unfit for signatures or integrity against a motivated attacker.
  • SHA-256 is the sensible default for new work. SHA-512 is not meaningfully more secure for most uses, though it is often faster on 64-bit hardware.
  • Hashing is not encryption — there is no key and no way back. If you need to recover the original value later, you want encryption, not a hash.
  • A digest changes completely when one bit of input changes, so comparing two hashes tells you whether inputs are identical but never how similar they are.
  • Whitespace counts. A trailing newline is why a hash computed here can differ from one computed over a file with the same visible content.
  • To verify a downloaded file against a published checksum, use your operating system tool (shasum or certutil) on the file itself — this tool hashes text you paste, not file contents.
  • Need to convert that hex digest to decimal or binary? Use the Number Base Converter.
  • Need a random unique identifier rather than a hash of specific content? Generate one with the UUID Generator.
  • Need a keyed hash for verifying message authenticity rather than a plain digest? Use the HMAC Generator.

Related tools

Browse all 8 Security tools

Frequently asked questions

10

Select SHA-256 from the algorithm selector, type or paste your text, and the hash appears instantly. All hashing runs in your browser using the Web Crypto API.

MD5, SHA-1, SHA-256, and SHA-512 are all available. SHA-256 is recommended for most use cases; SHA-512 produces a longer digest and is faster on 64-bit hardware.

SHA-512 produces a 512-bit (128 hex character) digest vs SHA-256's 256-bit (64 hex character) output. Both are secure; SHA-256 is the most widely used.

No — MD5 and SHA-1 are cryptographically broken and must not be used for password storage. Use bcrypt, scrypt, or Argon2 via a backend service instead.

All hashing is done entirely in your browser. SHA variants use the Web Crypto API (crypto.subtle.digest); MD5 uses a pure JavaScript implementation. Nothing is sent to a server.

No. MD5, SHA-1, SHA-256, and SHA-512 are all fast by design, which is exactly what makes brute-forcing cheap. Use bcrypt, scrypt, or Argon2, which are deliberately slow and salted.

Only as a non-adversarial checksum, such as detecting accidental corruption. Practical collision attacks exist for both MD5 and SHA-1, so neither is fit for signatures or integrity against a motivated attacker.

No. Hashing is one-way and has no key. If you need to recover the original value later you want encryption, not a hash.

Almost always whitespace or encoding. A trailing newline changes the digest completely, and the input must be treated as the same UTF-8 bytes on both sides.

Use your operating system tool — shasum on macOS and Linux, or certutil on Windows — because those hash the file bytes. This tool hashes text you paste into it rather than file contents.