Hash Generator
SHA-1, SHA-256, SHA-384 and SHA-512 for text or a file, computed in your browser.
MD5 is not offered. It has been broken for anything security-related since 2004, so it is not listed alongside SHA-256 as if the two were alternatives.
Digests all four, computed at once
Type something to see its digests.
Paste the checksum a download page gave you. The algorithm is worked out from its length.
How it works
- 1Type text, or choose a file. All four SHA digests are computed at once — there is no reason to make you pick first.
- 2Each digest is given in hex and in Base64, since different systems expect different encodings of the same bytes.
- 3To verify a download, paste the published checksum into the verify box. The algorithm is inferred from its length and the comparison is made for you.
- 4HMAC mode signs a message with a shared secret, which is what webhook signatures and API request signing use.
Common questions
- Why is there no MD5?
- MD5 has been broken since 2004 — two different files with the same MD5 can be produced on a laptop. Offering it in the same list as SHA-256 would imply they are alternatives, and they are not.
- Which one should I use?
- SHA-256 unless something tells you otherwise. It is what Git, TLS certificates and most published checksums use. SHA-512 is not meaningfully more secure for normal purposes, though it is faster on 64-bit hardware.
- Is SHA-1 safe?
- Not for anything security-related. A practical collision was demonstrated in 2017. It is still fine for spotting accidental corruption — Git uses it that way — but never for signatures, certificates or passwords.
- Can I use this to hash passwords?
- No. A plain SHA digest is far too fast, which is exactly what an attacker with a stolen database wants. Passwords need a deliberately slow algorithm with a per-user salt — bcrypt, scrypt or Argon2. This tool is for checksums and signatures.
- Why do "café" and "café" give different digests?
- Because they can be different bytes. An accented character can be stored as one code point or as a letter plus a combining accent. They look identical and hash differently. Normalise your text first if that matters.
- Is my file uploaded?
- No. Hashing happens in your browser through the Web Crypto API. The file never leaves your machine, which is the point when you are checking a private key or an installer.
Need to transport the data, not verify it?
Base64 encoding turns the same file into text that survives email and JSON — the right tool when you need to move bytes rather than check them.
Open the Base64 converterRelated tools
Base64 Encode and Decode
Convert text or a file to Base64 and back, with UTF-8 handled correctly.
Password Generator
Strong passwords and API keys from your browser’s cryptographic random source, never a server.
UUID Generator
Generate version 4 random UUIDs, or version 7 time-ordered ones that sort by creation.