Hash Generator

Generate an MD5, SHA-1, SHA-256 or SHA-512 hash of any text as a hex digest. Switch algorithms instantly. Computed entirely in your browser.

Loading tool…

Worked examples

  • SHA-256 of a short string

    The everyday case: SHA-256 is the default choice for checksums and content fingerprints in modern tooling (git, package managers, container images).

  • MD5 of an empty string

    Hashing empty input is a common sanity check when verifying a hashing pipeline behaves the same as a reference implementation.

  • SHA-1 of a longer sentence

    The classic pangram is a standard test vector for comparing hash function output against a known-correct reference value.

What this tool does

A cryptographic hash function takes any input and produces a fixed-length string of hex digits — a "digest" — that's effectively unique to that exact input. This tool computes an MD5, SHA-1, SHA-256 or SHA-512 hash of text entirely in your browser, switching between algorithms instantly.

When you need it

  • Generating a checksum to verify two pieces of text (or, after copying to a file-based tool, two files) are byte-for-byte identical.
  • Producing a content fingerprint for caching, deduplication, or comparing versions of a config or data file without storing the whole thing.
  • Matching a known test vector when implementing or debugging hashing code in another language, to confirm your implementation is correct.
  • Reproducing a hash algorithm's output for documentation, a tutorial, or answering "what does SHA-256 of X actually look like."

Choosing an algorithm

  • SHA-256 is the modern default for checksums and content fingerprints — used by git for commit and object identifiers (in newer configurations), package managers for verifying downloads, and container registries for image digests. Reach for this unless you have a specific reason not to.
  • SHA-512 produces a longer digest using the same family of algorithm as SHA-256, sometimes preferred where a larger output space is wanted or where it happens to be faster on 64-bit hardware.
  • SHA-1 and MD5 are both considered cryptographically broken — practical collision attacks exist for both, meaning two different inputs can be deliberately crafted to produce the same hash. They remain here for compatibility with legacy systems, checksums where an adversarial collision isn't a concern, and matching older reference values, not for anything requiring collision resistance.

What hashing is not for

None of these algorithms are appropriate for hashing passwords. They're designed to be fast, which is exactly the wrong property for password storage — a fast hash function lets an attacker who steals a password database try billions of guesses per second. Real password storage needs a deliberately slow, salted algorithm such as bcrypt, scrypt, or Argon2, specifically designed to resist that kind of brute-force attack. This tool doesn't offer those algorithms because a general-purpose text-hashing utility isn't the right place to build password storage — use a dedicated library in your application's backend instead.

Why the same input always produces the same hash

Hash functions are deterministic by design: given identical input, they always produce identical output, on any machine, at any time. That's what makes a hash useful as a fingerprint — if two files or strings produce the same hash, they're identical (for all practical purposes) with overwhelmingly high confidence, and if they differ by even one byte, the hashes will almost certainly be completely different, not just slightly different.

Limits

Input is capped at 2 MB of text. This is a text-hashing tool — hashing a file's exact bytes requires reading the file's binary content, which is a different operation from hashing the text you'd get by opening it in an editor (line-ending differences alone can change the hash).

Frequently asked questions

Is my text uploaded anywhere?
No. Hashing runs entirely in your browser; nothing is sent to a server — useful when the text is sensitive.
Which algorithm should I use?
SHA-256 for new checksums, content fingerprints or verifying file integrity. MD5 and SHA-1 are still common for legacy compatibility checks but are considered broken for any security purpose — never use them to protect a password.
Is this safe for hashing passwords?
No. These are fast, general-purpose hash functions meant for checksums and fingerprints, not password storage — a real password hash needs a slow, salted algorithm like bcrypt, scrypt or Argon2, none of which are offered here.
Why does the same input always produce the same hash?
That's the defining property of a hash function: it's deterministic, so the same input always maps to the same output, which is what makes hashes useful for verifying that two files or strings are identical.