Hash generator

Type some text or choose a file and see its MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes. Paste a checksum to see whether it matches. Your file never leaves your device.

  • Free
  • No sign-up
  • Runs in your browser
hash-generator

100% private — text and files are hashed in your browser and never uploaded.

How it works

Add text or a file

Type or paste text, or drop a file to get its checksum.

Read the hashes

All the common algorithms at once, each with a copy button.

Compare a checksum

Paste the one published by the source to check that the file is intact.

A fingerprint for data

A hash function turns any amount of data, a word or a huge file, into a short fixed-length string of characters, its hash or checksum. The same input always gives the same hash, but changing a single bit gives a completely different one, and it is practically impossible to work back from the hash to the input. That makes hashes useful as fingerprints: to check that a download arrived intact, to detect that a file has changed, to identify duplicates and as building blocks of digital signatures.

Which algorithm to use

  • SHA-256 is the standard today for integrity checks and the one that most software publishes next to its downloads. SHA-384 and SHA-512 are stronger variants with longer outputs.
  • SHA-1 and MD5 are old. Collisions can be manufactured for both, so they must not be used where an attacker could benefit, such as signatures or certificates. They remain widespread for detecting accidental corruption and in legacy systems, which is why they are still listed.

Verify a download

Websites often publish the checksum of a file they offer. Choose the file here, paste the published checksum into the comparison box and the tool tells you whether it matches any of the hashes. If it does, the file is what the publisher made. If not, the download was corrupted or altered, and you should not use it. The file is read in your browser and never uploaded.

HMAC

An HMAC mixes a secret key into the hash, so that only someone who knows the key can produce or check it. It is used to authenticate messages, sign API requests and webhooks. Tick the HMAC option, enter the key and you get HMAC-SHA-1, SHA-256, SHA-384 and SHA-512. MD5 is not offered for HMAC.

Hashes are not for storing passwords

A plain fast hash is the wrong tool for password storage, because attackers can test billions of guesses a second. Use a purpose-built algorithm such as Argon2, scrypt or bcrypt for that. This tool is for checksums and integrity.

What it does not do

Text is hashed as UTF-8, so the result may differ from another tool that uses a different encoding or that adds a line break at the end of the text. It does not crack hashes or look them up. Very large files are limited by your device's memory. To generate random values for keys and tokens, use the random string generator.

Frequently asked questions

How do I calculate the SHA-256 hash of a file?
Drop the file onto the box. The SHA-256 hash appears with the other algorithms. It is calculated in your browser and the file is not uploaded.
How do I check a downloaded file's checksum?
Choose the file, paste the checksum published by the source in the comparison box, and the tool shows whether it matches.
Which is better, MD5 or SHA-256?
SHA-256. MD5 is fast but broken for security purposes. It is still fine for spotting accidental corruption.
What is an HMAC?
A hash that includes a secret key, used to authenticate messages. Only someone with the key can produce the same value.
Can I get the original text from a hash?
No. Hashes are one-way. They can only be checked by hashing the same input again.
Are my files uploaded anywhere?
No. Text and files are processed in your browser.