Hash Generator
Input
Hashes
Paste a published checksum (MD5, SHA-1 or SHA-2) to verify it
About
A hash function converts any input into a fixed-length string. The same input always produces the same hash, but even a single character change produces a completely different result. MD5 and SHA-1 are no longer recommended for security-sensitive use cases.
How to use
1.
Type or paste text into the Input panel, or click Hash a file (or drop a file onto the panel)
2.
Copy a single hash from the Hashes list, or press Copy all to copy all five
3.
To verify a download, paste its published checksum into Compare with - the matching hash is highlighted
Common uses
▸
Verifying a download against the checksum published by its author
▸
Generating a SHA-256 checksum to publish alongside a file you distribute
▸
Checking whether two texts or two files are identical without comparing them directly
▸
Creating content fingerprints or cache keys
Similar tools
Frequently asked questions
Which hash algorithm should I use?
For security-sensitive uses, choose SHA-256 or stronger. MD5 and SHA-1 are broken - attackers can craft two different inputs with the same hash - so use them only to match checksums published in those formats, never to detect deliberate tampering.
Can I hash a file?
Yes. Click Hash a file, or drop a file onto the Input panel. To verify a download, paste its published checksum into Compare with: the matching hash is highlighted. The bare hex, a line of sha256sum output, or a labelled value such as sha256:... all work, in any letter case. The file is read and hashed locally in your browser and never uploaded. It is loaded into memory in one piece, so very large files (several gigabytes) may fail on devices with limited memory.
Can I use these hashes to store passwords?
No. Hashing is one-way, but MD5 and the SHA family are designed to be fast, so an attacker with a leaked hash can test billions of password guesses per second. Store passwords with a dedicated password-hashing function such as Argon2, bcrypt, scrypt, or PBKDF2, which are deliberately slow and salted.
Is my data sent to a server?
All hashing runs locally in your browser. SHA-1, SHA-256, SHA-384, and SHA-512 use the Web Crypto API; MD5 uses the spark-md5 library. Text and files never leave your device.
Why do two similar strings produce completely different hashes?
Hash functions are designed with the avalanche effect - even a single character change produces a completely different output, making accidental changes easy to detect.