Hash Generator

SHA-1, SHA-256, SHA-384 and SHA-512 for text or a file, computed in your browser.

MD5 is not offered. It has been broken for anything security-related since 2004, so it is not listed alongside SHA-256 as if the two were alternatives.

Digests all four, computed at once

Type something to see its digests.

Paste the checksum a download page gave you. The algorithm is worked out from its length.

How it works

  1. 1Type text, or choose a file. All four SHA digests are computed at once — there is no reason to make you pick first.
  2. 2Each digest is given in hex and in Base64, since different systems expect different encodings of the same bytes.
  3. 3To verify a download, paste the published checksum into the verify box. The algorithm is inferred from its length and the comparison is made for you.
  4. 4HMAC mode signs a message with a shared secret, which is what webhook signatures and API request signing use.

Common questions

Why is there no MD5?
MD5 has been broken since 2004 — two different files with the same MD5 can be produced on a laptop. Offering it in the same list as SHA-256 would imply they are alternatives, and they are not.
Which one should I use?
SHA-256 unless something tells you otherwise. It is what Git, TLS certificates and most published checksums use. SHA-512 is not meaningfully more secure for normal purposes, though it is faster on 64-bit hardware.
Is SHA-1 safe?
Not for anything security-related. A practical collision was demonstrated in 2017. It is still fine for spotting accidental corruption — Git uses it that way — but never for signatures, certificates or passwords.
Can I use this to hash passwords?
No. A plain SHA digest is far too fast, which is exactly what an attacker with a stolen database wants. Passwords need a deliberately slow algorithm with a per-user salt — bcrypt, scrypt or Argon2. This tool is for checksums and signatures.
Why do "café" and "café" give different digests?
Because they can be different bytes. An accented character can be stored as one code point or as a letter plus a combining accent. They look identical and hash differently. Normalise your text first if that matters.
Is my file uploaded?
No. Hashing happens in your browser through the Web Crypto API. The file never leaves your machine, which is the point when you are checking a private key or an installer.

Need to transport the data, not verify it?

Base64 encoding turns the same file into text that survives email and JSON — the right tool when you need to move bytes rather than check them.

Open the Base64 converter

Related tools