Generators tool

Hash Generator: MD5, SHA-256 and SHA-512 Online

Generate MD5, SHA-1, SHA-256 and SHA-512 hashes of text or a file, with optional HMAC. Compare a checksum to check a download. Nothing is uploaded.

Last updated

A hash generator turns any text or file into a short fingerprint. Change one character and the fingerprint changes completely. Type below, or pick a file, to see its MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes at once, then paste an expected hash to check it matches.

Showing the hashes of an empty string. Hashed as UTF-8.

Hashes hex

  • MD5Not for security

    —

  • SHA-1Not for security

    —

  • SHA-256

    —

  • SHA-384

    —

  • SHA-512

    —

Paste the checksum from a download page. Case, spaces and a 0x prefix are ignored.

Hashed in your browser. Text, keys and files never leave this device: files are read locally in chunks and are not uploaded. MD5 and SHA-1 are fine as checksums but broken for security.

Text is hashed as you type. A file is hashed on your device a piece at a time, with a progress bar for large ones, and is never uploaded.

How to use it

  1. Pick Text and type or paste, or pick File and choose or drop a file. Any size works.
  2. Read the hash you need from the list. Each one has its own Copy button.
  3. To check a download, paste the checksum from the download page into Compare with an expected hash. A match is ticked and the matching row is outlined.
  4. To sign a message, turn on HMAC with a secret key and enter the key. Every row becomes an HMAC, such as HMAC-SHA256.

Which hash should I use?

AlgorithmHex lengthSecure?Use it for
MD532No, brokenSpotting accidental corruption, old checksums, cache keys
SHA-140No, brokenGit object IDs, legacy systems that need it
SHA-25664YesThe default: checksums, signatures, webhooks, most things
SHA-38496YesSubresource Integrity (integrity="sha384-…"), TLS
SHA-512128YesA longer digest, when a spec or a download page asks for it

MD5 and SHA-1 are not for security. Both have practical collision attacks: someone can make two different files with the same hash. They still catch a download that was cut short or flipped a bit, but they cannot prove nobody swapped the file. Use SHA-256 when it matters.

None of these are for storing passwords. They are built to be fast, and fast is the wrong property for a password hash: an attacker with a leaked database can try billions of guesses a second. Use Argon2, bcrypt or scrypt, which are slow on purpose. For a new password, use the Password Generator.

Hash vs HMAC

A plain hash depends only on the data, so anyone can compute it. An HMAC mixes in a secret key, so it proves the message came from someone who knows the key and was not changed on the way.

This is how most webhooks are signed. GitHub sends X-Hub-Signature-256, Stripe sends Stripe-Signature, and both are an HMAC-SHA256 of the request body under a secret you share with them. To debug one, paste the raw body here, turn on HMAC, enter the secret, and compare with the header. The key is hashed as UTF-8 text.

Hashing in code

The same hashes from a terminal or in your own code:

WhereSHA-256MD5
macOS / Linuxshasum -a 256 file or sha256sum filemd5 file or md5sum file
Windows PowerShellGet-FileHash fileGet-FileHash file -Algorithm MD5
Bash, textprintf 'abc' | sha256sumprintf 'abc' | md5sum
JavaScript (browser)crypto.subtle.digest("SHA-256", bytes)not built in
Node.jscreateHash("sha256").update(s).digest("hex")createHash("md5")…
Pythonhashlib.sha256(b"abc").hexdigest()hashlib.md5(b"abc").hexdigest()
Gosha256.Sum256(data)md5.Sum(data)
C#SHA256.HashData(bytes)MD5.HashData(bytes)

For an HMAC, Python has hmac.new(key, msg, hashlib.sha256) and Node has createHmac("sha256", key). Compare HMACs with hmac.compare_digest or crypto.timingSafeEqual rather than ==, so the time taken does not leak how many characters matched.

Hash gotchas

  • The trailing newline. echo abc | sha256sum hashes abc plus a newline, so it will never match this page. Use printf or echo -n.
  • Line endings and encoding. The same text saved with Windows line endings (\r\n), a byte order mark, or as UTF-16 instead of UTF-8 has a different hash. This page always hashes UTF-8.
  • Hex is not the only format. Subresource Integrity and some APIs print the hash in Base64 rather than hex. It is the same bytes; the Base64 Encoder and Decoder shows the difference.
  • Case does not matter. A1B2 and a1b2 are the same hash, and the compare box ignores case.
  • Hashing is not encryption. You cannot get the input back from a hash. A site that "decrypts" MD5 is looking it up in a table of hashes of common words.
  • Password Generator for strong random passwords. Hash them with Argon2 or bcrypt on your server, never MD5.
  • UUID Generator for random IDs. Version 3 and 5 UUIDs are built from an MD5 and a SHA-1 hash of a name.
  • Base64 Encoder and Decoder, for hashes and signatures that arrive in Base64 rather than hex.
  • The Git cheat sheet. Every commit ID is a SHA-1 hash, and newer Git versions can use SHA-256 instead.
  • The Linux commands cheat sheet for sha256sum -c, which checks a whole list of checksums at once.

Common questions

Is this hash generator safe to use with private text and files?

Yes. Everything is hashed in your browser. Text, HMAC keys and files never leave your device: a file is read locally a chunk at a time and is never uploaded. The page records only that the tool was used and the settings, such as whether HMAC was on, never the text, the key, the file or the hash.

How do I use this as a SHA-256 generator online?

Type or paste text into the box and the SHA-256 hash appears straight away, along with MD5, SHA-1, SHA-384 and SHA-512. Tap Copy next to SHA-256 to copy it. For a file, switch to File and pick it; the hash appears when the progress bar finishes.

How do I check a file's checksum?

Switch to File, pick the file you downloaded, then paste the checksum from the download page into the compare box. It tells you whether it matches and which algorithm it matched, ignoring upper and lower case. This works as a checksum calculator for SHA-256, SHA-512, SHA-1 and MD5 checksums, which are the ones download pages publish.

Is MD5 still safe to use?

Not for security. MD5 has been broken since 2004: anyone can make two different files with the same MD5 hash in seconds, so it cannot prove a file was not tampered with, and it must never be used to store passwords. It is still fine as a quick checksum to catch a corrupted download, which is what this MD5 hash generator is for. SHA-1 is broken in the same way and should be treated the same.

What is the difference between a hash and an HMAC?

A hash depends only on the data, so anyone can compute it. An HMAC also mixes in a secret key, so only someone who knows the key can produce or check it. That is how webhooks from Stripe, GitHub and Slack prove a request came from them: they send an HMAC-SHA256 of the body, and you recompute it with the shared secret.

Why does my hash not match the one from another tool?

Almost always because the input differs by an invisible character. A trailing newline is the usual cause: echo adds one, so echo hello | sha256sum hashes hello followed by a newline. Use echo -n or printf. Windows line endings, a byte order mark and a different text encoding also change the hash. This page hashes text as UTF-8, exactly as typed.

Can a hash be decrypted or reversed?

No. A hash is a one-way function: there is no key and no way to run it backwards. Sites that claim to decrypt MD5 or SHA-256 are looking the hash up in a list of hashes of common passwords they have already computed, which is why short or common inputs are found and long random ones never are.

See all tools

Want this explained by a cat?

The videos cover the same ground in sixty seconds. If there is a tool you want built next, ask.