Hash generator: MD5, SHA-1, SHA-256 and SHA-512

Type text or drop a file to get its MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes at once, in hex or Base64. Paste a published checksum to check that a download matches. Files are hashed on your device and never uploaded. Use SHA-256 or stronger for integrity checks, because MD5 and SHA-1 are broken.

Free, no sign-up Runs in your browser

Input

Hashes

How to hash text or verify a file

  1. Type or paste text to see all five hashes update as you type. Text is converted to UTF-8 bytes first, as almost every other tool does.
  2. Or drop a file. It is read and hashed in your browser. Nothing is uploaded, so you can safely check private documents and large downloads.
  3. To verify a download, paste the checksum from the publisher's site into the compare box. The tool checks it against every algorithm, ignores upper or lower case, and shows Match or No match.
  4. Choose Hex or Base64. Hex is the usual format for checksums. Base64 is shorter and is used in places such as Subresource Integrity (integrity="sha384-…").

What a hash function does

A cryptographic hash turns any input into a short, fixed-length fingerprint. The same input always gives the same hash. Changing a single bit gives a completely different hash. And you can't work back from the hash to the input.

Worked example

SHA-256("abc") = ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
SHA-256("abd") = a52d159f262b2c6ddb724a61840befc36eb30c88877a4030b65cbe86298449c9
MD5("abc")     = 900150983cd24fb0d6963f7d28e17f72

One letter changed, and the whole hash changed. The first and last values are the official test vectors from FIPS 180-4 and RFC 1321, so you can type abc above to check this tool.

Which algorithm should you use?

AlgorithmOutputHex lengthStatus
MD5128 bits32Broken. Collisions can be made in seconds on a laptop.
SHA-1160 bits40Broken. A real collision was published in 2017.
SHA-256256 bits64Secure. The usual choice.
SHA-384384 bits96Secure.
SHA-512512 bits128Secure. The longest output.

MD5 and SHA-1 are broken for security. An attacker can create two different files with the same hash. Don't use them for signatures, certificates or to prove that a file hasn't been tampered with. They are still fine for spotting accidental damage, such as a corrupted download, and for matching old checksums.

For integrity, use SHA-256 or stronger. A hash only proves integrity if you get the expected value from a trusted source, such as the publisher's HTTPS site. A checksum stored next to the file on the same server can be replaced along with the file.

Never use a plain hash for passwords

SHA-256 is designed to be fast. A modern graphics card can try billions of guesses per second against a fast hash. Even with a salt, plain SHA-256 is not good enough for stored passwords. Use a dedicated password hashing function, which is slow on purpose and uses a unique salt per password:

  • Argon2id, the first choice for new systems.
  • scrypt, which also uses a lot of memory.
  • bcrypt, widely supported and still acceptable.

To create a strong password in the first place, use the password generator.

Tips

  • Line endings matter. "hello" and "hello" plus a line break have different hashes. Command-line tools such as echo add a line break unless you use echo -n.
  • Check from the command line: sha256sum file on Linux, shasum -a 256 file on macOS, or certutil -hashfile file SHA256 on Windows.
  • Large files are read into memory. Files of a few hundred megabytes are fine on most computers.

Frequently asked questions

Is MD5 still safe to use?
Not for security. MD5 collisions are easy to create, so it can't prove a file is genuine. It is still useful to detect accidental corruption or to match an old checksum. Use SHA-256 for anything that matters.
Can a hash be reversed or decrypted?
No. A hash is a one-way function, not encryption. But short or common inputs, such as simple passwords, can be found by guessing and comparing hashes, which is why passwords need bcrypt, scrypt or Argon2.
Why is my hash different from another tool's?
Usually the input differs: a trailing line break, a space, or a different text encoding. This tool hashes text as UTF-8 with no added line break. For files, the bytes are hashed exactly as stored.
How do I verify a downloaded file?
Drop the file here, then paste the checksum from the publisher's website into the compare box. If it says Match, the file is identical to the one they published.
Are my files uploaded?
No. Text and files are hashed in your browser with the Web Crypto API, and MD5 with a small built-in function. Nothing is sent to a server or saved. Only the hex or Base64 setting is remembered.

Last updated . How we check our tools.