About the Hash Generator
This hash generator computes the MD5, SHA-1, SHA-256 and SHA-512 digests of any text at the same time. Pick the algorithm you care about to see it highlighted along with its Base64 form, or paste an expected checksum to confirm that two values match. Text is hashed as UTF-8 bytes exactly as typed — including spaces and line breaks — so results agree with command-line tools such as sha256sum and md5sum when the input bytes are identical.
It is useful for developers checking API signatures and cache keys, sysadmins comparing checksums published next to a download, and anyone learning how cryptographic hash functions behave: change a single character and every digest changes completely.
All hashing happens locally in your browser, and nothing is sent to a server. Note that MD5 and SHA-1 are broken for security purposes (collisions can be produced), so use SHA-256 or SHA-512 for anything security-related, and a dedicated slow algorithm such as bcrypt or Argon2 for storing passwords.
How to use the hash generator
- 1Type or paste the text you want to hash.
- 2Choose the main algorithm — SHA-256 is the safe default.
- 3Copy the hex or Base64 digest, or read all four algorithms below.
- 4To verify a checksum, paste the expected value into the comparison box.
- 5If hashes don’t match a command-line result, try the trailing-newline option.
Formula and method
A cryptographic hash function H maps input of any length to a fixed-length digest: 128 bits for MD5, 160 bits for SHA-1, 256 bits for SHA-256 and 512 bits for SHA-512. The input is padded to a multiple of the block size (64 bytes, or 128 bytes for SHA-512) with its bit length appended, then each block is mixed into an internal state through many rounds of bitwise rotations, additions and logical functions (the Merkle–Damgård construction).
The final state is printed as hexadecimal (two characters per byte) or Base64. The same bytes always give the same digest, but even a one-bit change produces an unrelated result. This tool hashes the UTF-8 encoding of your text; different encodings or an extra newline produce different hashes.
- H
- The hash function (MD5, SHA-1, SHA-256 or SHA-512)
- digest
- Fixed-length output shown in hex and Base64
Worked examples
SHA-256 of "hello world"
The 11 bytes of "hello world" hash to the 64-character SHA-256 digest b94d27b9…efcde9. The same 32 bytes written in Base64 are uU0nuZNN…zek=, the form used in Subresource Integrity attributes.
MD5 checksum, uppercase, verified
The classic pangram is 43 bytes and its MD5 digest is 9e107d9d372bb6826bd81d3542a419d6. Pasting that value into the comparison box confirms a match, regardless of letter case.
Hash of an empty string
Even zero bytes have a well-defined hash. The empty-string SHA-256 value e3b0c442…b855 is worth recognising: if you see it in logs, something hashed an empty body or file.
Frequently asked questions
Can a hash be reversed or decrypted?+
No. Hash functions are one-way: there is no key and no decryption. Short or common inputs can be found by guessing (dictionary or rainbow-table attacks), which is why passwords need salted, deliberately slow algorithms.
Is MD5 still safe to use?+
MD5 is fine for non-security checksums such as detecting accidental file corruption or building cache keys. It is broken for security: attackers can create two different inputs with the same MD5, so never use it for signatures or certificates.
Why does my hash differ from sha256sum in the terminal?+
Usually because of a trailing newline: `echo "text"` adds \n before hashing, so its hash differs from the text alone. Use `echo -n "text" | sha256sum` (or printf) to hash exactly what you typed here, or add a final line break in the box to match plain echo. Different text encodings (UTF-16 vs UTF-8) also change the result.
Should I use SHA-256 to store passwords?+
Not on its own. SHA-256 is designed to be fast, which helps attackers guess billions of passwords per second. Use a password hashing function such as Argon2id, scrypt or bcrypt with a unique salt per user.
What is the difference between SHA-256 and SHA-512?+
Both belong to the SHA-2 family defined in FIPS 180-4. SHA-512 produces a 512-bit digest and uses 64-bit arithmetic, so it can be faster on 64-bit CPUs; SHA-256 produces 256 bits and is the more common choice for web APIs and blockchains.