Be Everywhere, Stay Undetectable. Manage multiple accounts safely with unlimited local profiles. Discover Undetectable. Learn More

Hash Generator: MD5, SHA-1, SHA-256, SHA-512

0 of 0 ratings
Everything is calculated in your browser. Your text and files are not uploaded and nothing is stored.
With a key you get HMAC values instead of plain hashes. The key stays in your browser.
Calculate
SHA-384 and SHA-512 are several times slower in a browser. Untick what you do not need for big files.

Hashes

Subresource Integrity (SHA-384)
The button copies the whole attribute for a script or link tag.

Compare with a given hash

Paste the checksum you were given: hex, Base64, or a whole line like “abc123… file.iso”.

Check against common passwords

A hash cannot be decrypted, but weak passwords can be guessed. This compares your hash with the hashes of the 10,000 most common passwords, in your browser.

Free Online Hash Generator: MD5, SHA-1, SHA-256, SHA-384 and SHA-512

Calculate the hash of a text or of a file with MD5, SHA-1, SHA-256, SHA-384 and SHA-512 at the same time. Everything is calculated in your browser: the text and the files are never uploaded, so it is safe for tokens, keys and private files. Files up to 2 GB are read in small pieces, so they do not have to fit in memory.

How to use it

  1. Text: type or paste the text, the hashes update as you type. The text is hashed exactly as you typed it (UTF-8), nothing is trimmed or escaped.
  2. File: switch to File and drop a file. Untick the algorithms you do not need to make big files faster; SHA-384 and SHA-512 are the slowest.
  3. HMAC: enter a secret key to get HMAC values instead of plain hashes, for example to check a webhook signature.
  4. Compare: paste the checksum you were given (hex, Base64 or a whole line of a checksum file) to see at once whether it matches.
  5. Copy a hash as lower-case hex, upper-case hex or Base64.

What is a hash?

A hash function turns data of any size into a short value of fixed length, the hash, digest or checksum. The same data always gives the same hash, a tiny change gives a completely different one, and the data cannot be restored from the hash. This makes hashes useful for checking that a download is intact, finding duplicate files, signing messages (HMAC) and storing password verifiers (with special slow hashes, see below).

Which algorithm to use?

AlgorithmLengthStatus and typical use
MD5128 bits, 32 hex charactersBroken for security (collisions can be created). Still fine for detecting accidental corruption, cache keys and ETags.
SHA-1160 bits, 40 hex charactersDeprecated: practical collisions exist. Legacy checksums, Git object IDs, HMAC-SHA1 in one-time password apps.
SHA-256256 bits, 64 hex charactersThe default choice today: checksums of downloads, certificates, Docker image digests, HMAC signatures.
SHA-384384 bits, 96 hex charactersThe usual hash of Subresource Integrity (integrity="sha384-...") and of some TLS cipher suites.
SHA-512512 bits, 128 hex charactersLarger security margin, fast on 64-bit processors, used in Linux password hashes ($6$) and signatures.

SHA-1, SHA-256, SHA-384 and SHA-512 belong to the SHA family designed by the NSA and standardised by NIST (SHA-2 is the name of the group that starts with SHA-224 and SHA-256). Other members such as SHA-224, SHA-512/256 and the SHA-3 family are rarely needed in practice, so this tool covers the algorithms people really use.

How to check the checksum of a downloaded file

Software vendors publish the SHA-256 (sometimes MD5 or SHA-1) of their files next to the download. Calculate the hash of the file you downloaded and compare: if it differs, the file is damaged or was replaced. Use the File tab, or the command line:

SystemCommand
Linuxmd5sum file.iso, sha1sum file.iso, sha256sum file.iso
macOSmd5 file.iso, shasum -a 1 file.iso, shasum -a 256 file.iso
Windows PowerShellGet-FileHash file.iso -Algorithm MD5 (or SHA1, SHA256, SHA384, SHA512)
Windows Command Promptcertutil -hashfile file.iso SHA256
Any system with OpenSSLopenssl dgst -sha256 file.iso

A checksum next to a download protects against a broken download only if you got the checksum from a trusted place, ideally a different one than the file. For protection against tampering, verify the digital signature as well.

Why is my hash different from md5sum?

The most common reason is the line break at the end. echo hello | md5sum hashes hello followed by a newline and gives b1946ac92492d2347c6235b4d2611184, while echo -n hello | md5sum hashes only the five letters and gives 5d41402abc4b2a76b9719d911017c592. Two switches under the text field reproduce both cases: add a line break at the end and Windows line breaks (CRLF). Other causes are different text encoding (this tool uses UTF-8) and a trailing space or invisible character in the copied text.

HMAC: signing with a secret key

HMAC mixes a secret key into the hash, so only someone who knows the key can produce or check the value. It is used to sign webhooks (GitHub, Stripe and many others send an HMAC-SHA256 of the request body), API requests and tokens. Type the message in the text field and the key in the secret field to see the HMAC of all five algorithms. On the command line the same is openssl dgst -sha256 -hmac "key".

Subresource Integrity (SRI)

SRI lets the browser check that a script or stylesheet loaded from a CDN has not been changed: <script src="https://cdn.example.com/lib.js" integrity="sha384-..." crossorigin="anonymous"></script>. Drop the file into the File tab (with SHA-384 ticked) and copy the ready integrity attribute from the SRI field.

Password hashing needs a different tool

Do not store passwords as MD5, SHA-1 or SHA-256: these functions are made to be fast, and a graphics card can test billions of guesses per second. Passwords must be stored with slow, salted algorithms such as bcrypt, scrypt or Argon2.

Frequently asked questions

Can a hash be decrypted?

No. A hash is not encryption, it throws information away. What is called “decrypting” is guessing: trying common words and comparing their hashes. The tool has a check against common passwords box that does exactly this locally, with a list of the 10,000 most common passwords.

Is my data uploaded?

No. The hashes are calculated by JavaScript on your device. You can disconnect from the internet after the page has loaded and it will keep working.

What is the maximum file size?

2 GB. The file is read in pieces of 4 MB, so memory use stays small. The speed depends on the computer: MD5 is the fastest, SHA-384 and SHA-512 are several times slower in the browser.

Which hash should I publish with my download?

SHA-256. It is supported by every platform and has no known weaknesses. Add the signature of the file if users must be protected against tampering.

Similar tools

MD5 Hash Generator

Free online MD5 hash generator and checker: MD5 of a text or a file up to 2 GB, compare with a given checksum, check against common passwords. Calculated in your browser, nothing is uploaded.

5
SHA-256 Hash Generator

Free online SHA-256 hash generator: SHA-256 and HMAC-SHA256 of a text or a file up to 2 GB, compare with a given checksum. Calculated in your browser, nothing is uploaded.

3
SHA-1 Hash Generator

Free online SHA-1 hash generator: SHA-1 of a text or a file up to 2 GB, compare with a given checksum. Calculated in your browser, nothing is uploaded.

3
Base64 Encoder / Decoder

Encode text to Base64 or decode Base64 back to text online, instantly in your browser. UTF-8 and URL-safe Base64 supported.

12

Popular tools