Hash generator
Calculate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 of text or a file, then compare with a published checksum.
Calculation and conversion of the text and files you enter happen in your browser, and the tool does not send your original input or results to a server. For traffic related to visit statistics and ads, see the privacy policy.
How to use it
- Choose the Text tab and type or paste your text, or choose the File tab and drop a file onto the box. Hashes appear as soon as there is input.
- Untick the algorithms you do not need. Fewer algorithms means less work for large files.
- Pick lowercase or uppercase to match the format the other side uses, then press Copy next to the hash you need.
- To verify a download, paste the checksum published by the vendor into the compare box. The tool tells you whether it matches one of the computed hashes and which algorithm it matched.
Examples
The classic test string
Text input of three letters. These values appear in the official MD5 and SHA test vectors, so you can use them to check the tool itself.
- Input
abc
- Result
MD5 900150983cd24fb0d6963f7d28e17f72 SHA-1 a9993e364706816aba3e25717850c26c9cd0d89d SHA-256 ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
Verifying a downloaded file
Drop the downloaded file on the File tab, paste the SHA-256 value from the download page into the compare box, and read the result. A match means the file is byte for byte what the publisher hashed. A mismatch means the download is incomplete, damaged or different.
Details
A hash function turns any input into a short fixed-length fingerprint. The same input always gives the same fingerprint, and a tiny change in the input changes the fingerprint completely. That makes hashes useful for checking that a file arrived intact and for spotting accidental changes in text.
This page computes five common hashes. MD5 and SHA-1 are still widely published next to downloads, but practical collision attacks exist for both, so do not rely on them where someone might forge a file on purpose. SHA-256, SHA-384 and SHA-512 belong to the SHA-2 family and are the better choice for integrity checks today. A hash is not encryption: it cannot be reversed to recover the input, and it is not a safe way to store passwords by itself.
Text is converted to UTF-8 bytes before hashing, so the same characters always give the same result regardless of your operating system. Line endings count as characters: a text that ends with a newline has a different hash from the same text without one, which is the usual reason this tool disagrees with a command such as echo piped into sha256sum. Files are hashed byte for byte exactly as they are stored on your disk.
SHA-1, SHA-256, SHA-384 and SHA-512 of text and of files up to 64 MB are computed with the Web Crypto API built into your browser. MD5, and any larger file, use a built-in implementation that reads the file in 8 MB pieces on a background thread, so the page stays responsive and memory use stays low even for multi-gigabyte files.
Frequently asked questions
Does the file I choose get uploaded?
The tool reads the file inside your browser and does not send the file or the resulting hashes to a server. This page also carries no ads or analytics code, so nothing else on the page can read what you enter.
Why is my hash different from the one my terminal prints?
Most often it is a trailing newline. echo abc | sha256sum hashes four bytes (abc plus a newline), while typing abc here hashes three. Use printf abc | sha256sum or echo -n abc to compare. Another cause is different text encoding: this tool always hashes UTF-8.
Is MD5 safe to use?
MD5 is fine for catching accidental corruption, such as a broken download. It is not safe against someone who wants to forge a file, because collisions can be produced deliberately. Prefer SHA-256 or SHA-512 whenever the publisher offers them.
Can I recover the original text from a hash?
No. A hash discards information on purpose. Short or common inputs can be guessed by hashing candidates and comparing, which is why plain hashes are not suitable for storing passwords.
How large a file can it handle?
Files larger than 64 MB are read in pieces, so memory use stays small. Large files take longer because every selected algorithm has to read the whole file. Untick the algorithms you do not need to speed it up.