Hash Generator

Input

Output format
EmptyUTF-8

Digests

Enter text or add a file to see all five digests at once.

5 algorithms · 128–512 bithex, lowercase
Algorithm reference
AlgorithmBitsCollision resistanceRecommended use
MD5128Broken — practical collisions since 2004Non-security checksums only: corruption detection, cache keys, dedup. Never for passwords, signatures, or anything an adversary could influence.
SHA-1160Broken — first public collision in 2017 (SHAttered)Legacy interop only (old Git object hashing, some existing certificate chains being phased out). Not for new security-sensitive designs.
SHA-256256No known practical attackDefault general-purpose choice: checksums, content-addressing, HMAC keys, TLS certificate fingerprints.
SHA-384384No known practical attackSame use cases as SHA-256 where a larger output/margin is wanted, or where a standard mandates it.
SHA-512512No known practical attackSame tier as SHA-256/384; often faster than SHA-256 on 64-bit hardware despite the larger output.

None of these are password hashes. Even SHA-512 is a fast general-purpose digest, designed to be computed quickly — exactly the wrong property for password storage, since it makes brute force cheap. Password storage needs a slow, memory-hard KDF (bcrypt, scrypt, Argon2), which this tool does not implement.

"Collision resistance" means resistance to an attacker deliberately finding two inputs with the same hash — a separate property from preimage resistance (guessing the input from the hash), which is also weaker for MD5/SHA-1 but to a lesser practical degree.

About this Hash Generator

Hash text or a file with MD5, SHA-1, SHA-256, SHA-384, and SHA-512 at once — with optional HMAC and a hash to verify against, directly in your browser.

Digests are computed locally as you type or drop in a file — nothing is uploaded, files included. MD5 and SHA-1 are included for checksum and legacy-interop lookups; neither is collision resistant, so use SHA-256 or stronger for anything security related. Turn on HMAC to key every digest with a secret, switch the output format between lowercase, uppercase, or Base64, or paste a known-good hash into Compare to check it against all five digests at once.

FAQ

Should I use MD5 or SHA-1 to hash passwords?

No — never. Both are cryptographically broken and fast enough to brute-force on modern hardware. Use the Bcrypt Hash tool for passwords instead — it's deliberately slow and salted, which is what password hashing needs.

Which algorithm should I use for file integrity checks?

SHA-256 is the standard choice — used in TLS, code signing, and most "give me a hash" situations. MD5/SHA-1 still work for catching accidental corruption, just not anything security-sensitive.

Will this match md5sum / sha256sum / openssl dgst output?

Yes — hashing is deterministic and standardized; identical input bytes always produce the identical digest, regardless of tool.

Why did the hash change completely when I only fixed a typo?

Expected — cryptographic hash functions are designed so a one-character change produces a completely different, unpredictable output (the avalanche effect).

Can I hash a file, not just text?

Yes — switch to file mode, or drag a file onto the input, and it hashes the raw bytes directly. Nothing is uploaded; the file never leaves your browser.

Is my file or text uploaded anywhere?

No — hashing runs entirely in your browser via the Web Crypto API. A hash generator is exactly the kind of tool people paste client files or proprietary text into without a second thought — here, nothing is transmitted.

Related tools