Hash generator: MD5, SHA-1, SHA-256 and SHA-512
Calculate MD5, SHA-1, SHA-256 and SHA-512 hashes of text or a file in one go. Compare with a published hash to check that a download is intact.
A hash is not encryption: it is a one-way fingerprint that cannot be turned back into the data. Plain SHA-256 is not safe for storing passwords; use a dedicated method such as bcrypt or Argon2.
Hash values
- MD5Legacy128 bits, 32 hex characters
- SHA-1Legacy160 bits, 40 hex characters
- SHA-256256 bits, 64 hex characters
- SHA-512512 bits, 128 hex characters
MD5 and SHA-1 are broken: different data with the same hash can be crafted on purpose. They are fine for spotting accidental corruption of a download, but do not use them for security (tamper protection, signatures, passwords).
Paste the hash published by the source to check that it matches. Case and surrounding spaces are ignored.
Files you select are processed in your browser on this device. They are never uploaded to or stored on our server. For how analytics are handled, see the Privacy Policy.
How to use
- Choose "Text" or "File".
- Enter text and press "Calculate hash", or choose a file (it is hashed as soon as you select it).
- The MD5, SHA-1, SHA-256 and SHA-512 values appear. Copy each one with its button, and switch to uppercase if you need it.
- To verify, paste the expected value into "Expected hash to compare"; the tool shows whether it matches and which algorithm matched.
Supported formats and limits
- Files up to 100 MB and text up to 5 MB. The whole file has to be read into memory, so the limit is kept conservative for phones.
- Text is hashed as UTF-8 bytes. Line breaks and trailing spaces count, so any difference changes the result. Browsers turn line breaks in the text box into LF, so to match a file with CRLF line endings, hash the file itself.
- Hashing (Web Crypto) only works on pages served over https.
- MD5 and SHA-1 are broken: different data with the same hash can be made on purpose. They are fine for spotting accidental corruption, but not for security such as tamper protection or passwords.
How it works
SHA-1, SHA-256 and SHA-512 are calculated with the browser's built-in crypto.subtle.digest. MD5 is not part of Web Crypto, so it comes from the audited open-source library @noble/hashes (MIT license). Results are shown as lowercase hexadecimal.
The comparison ignores surrounding spaces and letter case and uses only the first word, so a sha256sum line ("hash filename") can be pasted as is.
A hash is a one-way value, not encryption. Plain SHA-256 is too fast for storing passwords and can be brute-forced; use a dedicated method such as bcrypt, scrypt or Argon2.
FAQ
Is my file uploaded?
No. The file is read and hashed in the browser on your device and never sent to our server.
How do I check that a download is genuine?
Paste the SHA-256 (or other) value published by the source into "Expected hash to compare", then choose the file. "Match" means the contents are identical.
Should I still use MD5 or SHA-1?
They still catch accidental corruption, but they cannot detect deliberate tampering. If the source also publishes SHA-256, compare with that.
The same text gives a different hash.
A trailing line break or space, or a different character that looks the same, changes the hash. Windows (CRLF) and Unix (LF) line endings also give different results.
Can a hash be turned back into the original data?
No. However, short strings and guessable passwords can sometimes be found by trying many inputs.
Related guides
- Base64 is not encryption: encoding, encryption and hashing explainedWhat Base64 actually does, why it does not protect secrets, how it differs from encryption and hashing, and how to encode and decode text and files.
Related tools
Last updated: