SHA-1 hash generator

Type or paste text, or drop a file, and get its SHA-1 hash (40 hexadecimal characters) instantly, next to the other common hashes. Everything is computed in your browser.

  • Free
  • No sign-up
  • Runs in your browser
sha1-generator

100% private — text and files are hashed in your browser and never uploaded.

How it works

Enter your text or file

Type or paste text, or drop a file of up to 500 MB. Nothing is uploaded.

Read the SHA-1 hash

The hash updates as you type. Choose lowercase or uppercase hexadecimal, or Base64.

Copy or compare

Copy the hash with one click, or paste a known hash in the compare box to check that they match.

How to generate a SHA-1 hash

To generate a SHA-1 hash, type or paste your text in the box above, or drop a file on it. The 40-character SHA-1 checksum appears at once, together with the other common hashes, and you can copy any of them. Everything is computed in your browser, so the text and files you hash are never uploaded. For example, the SHA-1 of the word hello is aaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d.

What is SHA-1?

SHA-1 (Secure Hash Algorithm 1) was published by the US standards body NIST in 1995 as FIPS 180-1. It turns any input into a 160-bit fingerprint, shown as 40 hexadecimal characters. It was the workhorse of web security for two decades and is still everywhere in older software.

SHA-1 examples

SHA1 of some sample texts
TextSHA-1 hash
(empty)da39a3ee5e6b4b0d3255bfef95601890afd80709
helloaaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d
Hellof7ff9e8b7bb2e09b70935a5d785e0cc5d9d0abf0
hello world2aae6c35c94fcfb415dbe95f408b9ce91ee846ed
UtilsDock418e21fd463c9d013b6fe166866f8da5bf9a17c6

What SHA-1 is used for

  • Git object IDs: every commit, tree and file in a classic Git repository is named by its SHA-1.
  • Checking older downloads and mirrors that only publish a SHA-1 checksum.
  • Legacy protocols, including HMAC-SHA1 in OAuth 1.0 and some older payment and API integrations.
  • Deduplication and change detection, where nobody is trying to forge a collision.

Limits and security notes

SHA-1 is deprecated for security. In 2017 Google and CWI Amsterdam published the first real collision, two different PDF files with the same SHA-1, which took about 9 quintillion computations. Browsers stopped trusting SHA-1 certificates that year. For anything where an attacker could benefit from a collision, such as signatures, certificates or software updates, use SHA-256 or SHA-512.

Private by design

The hash is computed by your own browser with the Web Crypto API (and a built-in routine for MD5, which Web Crypto does not offer). Nothing you type and no file you drop is sent to a server, so it is safe to hash private text and internal files.

Frequently asked questions

Is SHA-1 still safe to use?
Not for security. It is fine for non-adversarial uses such as change detection or legacy compatibility, but collisions can now be produced deliberately, so new designs should use SHA-256 or better.
How long is a SHA-1 hash?
40 hexadecimal characters, which is 160 bits, for any input. The empty string gives da39a3ee5e6b4b0d3255bfef95601890afd80709.
What is the difference between SHA-1 and SHA-256?
SHA-256 belongs to the newer SHA-2 family, produces a 256-bit (64-character) hash and has no known practical attack, while SHA-1 gives 160 bits and has known collisions.
Are the hashes case sensitive?
The hexadecimal digits a-f and A-F mean the same thing, so a hash in uppercase is equal to the same hash in lowercase. Use the uppercase option only when the system you copy it into expects that format.
Is this converter free?
Yes. There is no sign-up and no limit, and it runs in your browser, so nothing you type is sent to a server.
Does it work on a phone?
Yes. It works in any modern mobile browser, and the result updates as you type.