// security

Hash Generator.

Generate MD5, SHA-1, SHA-256, and SHA-512 hashes from text or files. All hashing happens in your browser.

Client-sidecrypto.subtleNo upload

Text input

Hashes

What are hashes?

A hash function takes any input — a string, file, or binary data — and produces a fixed-size string of characters that acts as a fingerprint. The same input always produces the same hash, but you can't reverse a hash to get the original input. Even a tiny change in input (one bit) produces a completely different hash, making hashes useful for verifying data integrity.

This tool computes five hash algorithms simultaneously: MD5, SHA-1, SHA-256, SHA-384, and SHA-512. Each produces a different output length and offers different security guarantees. For most non-security use cases (checksums, cache keys, data fingerprinting), any algorithm works. For security applications (passwords, signatures, certificates), use SHA-256 or stronger.

Hash algorithms compared.

MD5 (128-bit, 32 hex chars) — fast but cryptographically broken. Collisions have been found. Use only for checksums, not security. SHA-1 (160-bit, 40 hex chars) — deprecated for security but still used in Git commit IDs and some legacy systems. SHA-256 (256-bit, 64 hex chars) — current standard for most security applications. Used in TLS certificates, Bitcoin, and password hashing (when combined with salt).

SHA-384 (384-bit, 96 hex chars) — part of the SHA-2 family with a larger output. Used in high-security applications and government systems. SHA-512 (512-bit, 128 hex chars) — the largest SHA-2 variant. Offers the highest security margin but is slower and produces longer hashes.

Common use cases.

Data integrity. Hash a file before and after transfer to verify it wasn't corrupted. If the hashes match, the data is identical. Cache keys. Use a hash of the input as a cache key to detect when the input has changed and the cache needs refreshing. Deduplication. Hash files to find duplicates — files with the same hash are (almost certainly) identical.

Password hashing. Don't use this tool for password storage. Passwords need slow, salted hash functions like bcrypt, scrypt, or Argon2. Fast hashes like SHA-256 can be brute-forced billions of times per second on modern hardware.

Choosing the right algorithm.

For non-security purposes like checksums, cache busting, or generating short identifiers, MD5 or SHA-1 are fine — they're fast and produce shorter output. For anything involving trust, authentication, or data integrity verification, always use SHA-256 or stronger. SHA-256 is the minimum standard for TLS certificates, code signing, and blockchain systems.

In practice, most developers reach for SHA-256 as the default choice. It strikes a good balance between security and performance. SHA-384 and SHA-512 offer larger output but are rarely needed unless you're working with government compliance standards (like FIPS 140-2) or need extremely high collision resistance. The difference in security between SHA-256 and SHA-512 is negligible for nearly all real-world applications.

When comparing hashes, always use a constant-time comparison function rather than simple equality checks. Timing attacks can leak information about hash values when comparisons are performed naively. For most web applications, this is handled automatically by your framework or language's hash comparison utilities.

The hashes shown here are displayed in hexadecimal format, which is the most common representation. Binary or Base64 encodings are occasionally used in protocols, but hex strings are easier to read, compare, and paste into configuration files.

FAQ

Why is MD5 not safe for passwords anymore?

MD5 is fast and broken — modern GPUs compute billions of MD5s/sec, so rainbow tables and brute-force crack common passwords in seconds; use bcrypt, scrypt, or Argon2 for passwords.

What's the difference between MD5, SHA-1, SHA-256, and SHA-3?

All are cryptographic hash functions but with increasing security: MD5 (broken), SHA-1 (deprecated), SHA-256 (still secure for non-password use), SHA-3 (newest, NIST standard).

Can I reverse a SHA-256 hash back to the original text?

No — SHA-256 is a one-way function by design; you can only brute-force common inputs (rainbow tables) or look up the hash in a database like CrackStation for weak passwords.

What's the right hash function for file integrity checks?

SHA-256 is the standard for file checksums; SHA-512 if you want extra security. Avoid MD5/SHA-1 — collisions have been found for both.

How do I generate a hash of a file in the command line?

`sha256sum file.txt` (Linux), `shasum -a 256 file.txt` (macOS), or `certutil -hashfile file.txt SHA256` (Windows); all produce the same hex digest for the same file.