Hash Generator (MD5, SHA)

Hash text with MD5, SHA-1, SHA-256, SHA-512 or CRC32 in your browser. UTF-8 bytes, so the digest matches what md5sum and shasum produce.

Enable JavaScript to customise; default output below.

Nothing is uploaded. The hashing happens in this tab.

Algorithms

SHA-256 unless something specific asks for another. CRC32 is a checksum, not a hash.

More options Show
Live preview hashes.txt
md5     9e107d9d372bb6826bd81d3542a419d6
sha1    2fd4e1c67a2d28fced849ee1bb76e7391b93eb12
sha256  d7a8fbb307d7809469ca9abcb0082e4f8d5651e46d3cdb762d02d0bf37c9e592
sha512  07e547d9586f6a73f73fbac0435ed76951218fb7d0c8d788a309d785436bbb642e93a252a954f23912547d1e8a3b5ed6e1bfd7097821233fa0538f3db854fee6

# md5, sha1: fine as a checksum, unsafe for passwords, signatures or integrity against an attacker.

Output is valid and updates as you type.

Hash text with MD5, SHA-1, SHA-256, SHA-512 or CRC32, in your browser. The digests match what md5sum and shasum give for the same bytes.

How to use

  1. Paste the text. It is hashed as UTF-8 bytes, which is what command line tools and most languages do by default.
  2. Pick the algorithms. SHA-256 unless something specific asks for another one.
  3. Compare digests by eye on the first and last four characters; a mismatch anywhere means the input differs somewhere.
  4. Copy what you need. Nothing is uploaded, so a file’s contents or an API response can be hashed safely here.

Example

The quick brown fox jumps over the lazy dog gives:

md5     9e107d9d372bb6826bd81d3542a419d6
sha1    2fd4e1c67a2d28fced849ee1bb76e7391b93eb12
sha256  d7a8fbb307d7809469ca9abcb0082e4f8d5651e46d3cdb762d02d0bf37c9e592

Change one character, even the case of one letter, and every digest changes completely. That is the avalanche property, and it is why a hash works as a fingerprint.

Pitfalls

  • MD5 and SHA-1 are broken for security. Collisions can be manufactured, so they cannot prove a file has not been tampered with. As a checksum against accidental corruption they are still fine.
  • A hash is not encryption. There is no way back, which is the point; anyone offering to “decrypt” an MD5 is running a lookup table.
  • Never store a password as a plain hash, however strong the algorithm. Password hashing needs bcrypt, scrypt or Argon2, which are deliberately slow and salted.
  • The encoding decides the digest. Hashing the UTF-16 representation of the same text gives a different answer, which is the usual reason two languages disagree about a hash.
  • A trailing newline is part of the input. echo text | md5sum hashes the newline too, which is why a terminal digest often differs from a copy and paste.
  • CRC32 is an error-detecting checksum, not a hash. It is 32 bits, collisions are easy, and it exists to catch a flipped bit in transit.
  • Hashing a file is not the same as hashing its text. Line endings, byte order marks and trailing whitespace all change the result.
  • Two different files with the same SHA-256 have never been found. Two with the same MD5 can be generated on a laptop in seconds.

Compatibility

MD5 follows RFC 1321, SHA-1 and the SHA-2 family follow FIPS 180-4, and CRC32 uses the IEEE 802.3 polynomial that zip and PNG use. The digests were checked against md5, shasum and Python’s hashlib for ASCII, accented text and multi-block input. Everything runs in your browser: MD5 is implemented here because the browser’s own crypto API does not offer it and is asynchronous, which a page that renders its output on the server cannot use.

Frequently asked questions

Which algorithm should I use?
SHA-256 for anything new. MD5 or CRC32 only when an existing system or format requires them.
Can I hash a file?
Not in this tool; it takes text. For a file, shasum -a 256 file in a terminal is the reliable way.
Why does my digest differ from the server’s?
Almost always a trailing newline, a different encoding, or whitespace. Hash the exact same bytes and the digests match.
Is my text uploaded?
No. The hashing happens in this tab.
What about HMAC?
That needs a key and a slightly different construction. It is a separate job from hashing a string.
Weekly drops

New tools, when there are new tools

One email when something worth using ships. No schedule to fill, so no filler.

Your address goes nowhere else, and one click unsubscribes.