Enter your text or file
Type or paste text, or drop a file of up to 500 MB. Nothing is uploaded.
Type or paste text, or drop a file, and get its SHA-256 hash (64 hexadecimal characters) instantly, next to the other common hashes. Everything is computed in your browser.
100% private — text and files are hashed in your browser and never uploaded.
Keep going with your result in another tool. Nothing is uploaded.
Type or paste text, or drop a file of up to 500 MB. Nothing is uploaded.
The hash updates as you type. Choose lowercase or uppercase hexadecimal, or Base64.
Copy the hash with one click, or paste a known hash in the compare box to check that they match.
To generate a SHA-256 hash, type or paste your text in the box above, or drop a file on it. The 64-character SHA-256 checksum appears at once, together with the other common hashes, and you can copy any of them. Everything is computed in your browser, so the text and files you hash are never uploaded. For example, the SHA-256 of the word hello is 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824.
SHA-256 is the most widely used member of the SHA-2 family, published by NIST in 2001 as part of FIPS 180-2. It turns any input into a 256-bit fingerprint written as 64 hexadecimal characters. No practical attack on it is known, which is why it is the default choice for integrity checks today.
| Text | SHA-256 hash |
|---|---|
(empty) | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
hello | 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824 |
Hello | 185f8db32271fe25f561a6fc938b2e264306ec304eda518007d1764826381969 |
hello world | b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9 |
UtilsDock | c6c632a4a7a867f3d6f3c0d8de350b5d4dd06598b83dd0230c46a53e917a3885 |
SHA-256 is fast by design, which makes it the wrong tool for storing passwords: an attacker can try billions of guesses per second. For passwords use a slow, salted algorithm such as Argon2id, bcrypt or scrypt. SHA-256 also has no key of its own, so to authenticate a message use HMAC-SHA256 instead of hashing the secret and the message together.
The hash is computed by your own browser with the Web Crypto API (and a built-in routine for MD5, which Web Crypto does not offer). Nothing you type and no file you drop is sent to a server, so it is safe to hash private text and internal files.
More utilities that also run without leaving your browser.