Hash generator — MD5, SHA-1, SHA-256, SHA-384 and SHA-512
Type text or pick a file and get all five digests at once, in lowercase hex with an uppercase toggle. Paste the checksum a download page published and the comparison is done for you — the length alone tells us which algorithm it is, so you do not have to know. Files are read straight off your disk by this page; nothing is uploaded, and nothing is saved.
- Nothing is uploaded or saved — files are read locally
- SHA-1 to SHA-512 from the browser, MD5 written in
- Works offline once the page has loaded
Everything here runs in your browser. Text is hashed as UTF-8; files are read straight from disk in chunks. Nothing is uploaded, and nothing is saved.
Hashing…
MD5 and SHA-1 are listed because checksums are still published with them, not because they are safe. Deliberate collisions can be produced for both, so they catch accidental damage — a truncated download, a bad mirror — and nothing else. Use SHA-256 or better when it matters.
Paste the hash from the download page. Case is ignored, and the “hash filename” line that shasum prints can be pasted whole. The length names the algorithm, so you do not have to know which one was used.
The five algorithms, and which to trust
Every length below is fixed by the algorithm and can be checked against the output above: the digest never changes size, however large or small the input is.
MD5
Broken for security128 bits · 32 hex characters
Published in 1992 and still everywhere on download pages. Collisions can be produced on demand, so it proves nothing against a deliberate attacker — but it still catches a truncated or corrupted file, which is what most people use it for. Not available from the browser's crypto API; this page implements it directly.
SHA-1
Broken for security160 bits · 40 hex characters
The successor to MD5, and retired for the same reason: a practical collision was demonstrated publicly in 2017, and browsers and certificate authorities dropped it. Git still uses it for object ids, and legacy systems still publish it. Fine as a checksum against accidents, unsafe as a signature.
SHA-256
Recommended256 bits · 64 hex characters
The default choice, and the one most projects publish today. No practical collision attack is known. If a download page offers more than one checksum, this is the one to compare.
SHA-384
Strong384 bits · 96 hex characters
SHA-512 with a different starting state and the output truncated. Chosen mostly to match a required security level in TLS suites and certificates rather than for file checksums.
SHA-512
Strong512 bits · 128 hex characters
The 64-bit member of the SHA-2 family. On 64-bit hardware it is often faster than SHA-256 despite the longer output, which is why some projects publish it in preference.
How it works
- 1
Choose text or a file
Text is hashed as UTF-8, which is what every command-line tool uses, so the answers match. A file is read in chunks straight from disk into memory and hashed there — it is never uploaded, and the progress figure is the file being read, not sent.
- 2
Read all five digests
Every algorithm is computed from the same bytes at the same time, so you can compare against whichever one a download page happened to publish. Output is lowercase hex by default because that is what shasum and sha256sum print; the toggle switches to uppercase for the sites that publish it that way. Case never affects whether two hashes are the same.
- 3
Paste the published checksum
Drop the expected hash into the compare field and you get a verdict instead of counting characters across a 64-digit string by eye. The comparison ignores case, tolerates the "hash filename" format that shasum prints, tolerates a "sha256:" prefix, and tolerates hashes published in spaced groups. It names the algorithm it matched, which is often the only way to find out which one the publisher used.
- 4
Know which answer to trust
A checksum match proves the bytes are identical to the bytes the publisher hashed. That catches a truncated download, a corrupted disk or a bad mirror. It only proves the file is genuine if the checksum itself came from somewhere trustworthy — and for that, MD5 and SHA-1 are no longer enough, because both can be made to collide deliberately.
Frequently asked questions
Is my file uploaded?
No. Picking a file hands this page a read-only handle to it; the bytes are read in chunks with the browser's own file API and hashed in the tab. There is no server behind this site to upload to. Nothing is written to localStorage either, so nothing survives closing the tab. The progress bar is the file being read off your disk, not a transfer.
Can a hash be turned back into the original?
No. A hash is one-way by design: it maps input of any length onto a fixed number of bytes, so information is thrown away and there is nothing left to reverse. What sites that claim to "decrypt" a hash actually do is look it up in a table of hashes of common inputs — which works beautifully for "password1" and not at all for a 5 MB file. Hashing is not encryption, and it has no key.
Why does the same input always give the same hash?
Because the algorithm is a fixed sequence of arithmetic on the bytes, with no randomness and no clock in it. That is the property the whole idea depends on: it is why a checksum computed on your machine can be compared with one computed on the publisher's two years earlier, and why any correct implementation anywhere gives the same answer for the same bytes.
What is a collision, and why does it matter?
A collision is two different inputs with the same hash. They must exist — a fixed-size output cannot uniquely represent inputs of unlimited length — so the question is only whether anyone can produce a pair on purpose. For MD5 and SHA-1 they can, and have; both are considered broken for anything security-related. They remain perfectly good at catching accidents like a truncated download, because random corruption does not produce a collision. SHA-256 and above have no practical collision attack.
My hash does not match the one on the download page — what now?
For a file, first check you compared against the same algorithm; the compare field here names it for you. Then re-download, because a truncated or mirror-corrupted file is the usual cause. For text, the difference is almost always invisible: a trailing newline, Windows CRLF line endings against Unix LF, a non-breaking space pasted from a web page, or a different text encoding. Hashes are computed over bytes, and all four of those change the bytes.
Should I hash passwords with SHA-256?
No. General-purpose hashes are built to be fast, which is precisely wrong for passwords — speed is what lets an attacker try enormous numbers of guesses against a stolen table. Password storage wants a slow, salted, purpose-built function such as bcrypt, scrypt or Argon2, with a work factor you can raise as hardware gets faster. This tool is for checksums and fingerprints, not for storing credentials.
How large a file can this handle?
Up to 512 MB here. The limit is the browser, not the algorithm: the bytes have to sit in one contiguous block of memory for the browser's crypto API, and a phone will kill the tab long before a DVD image finishes. For anything bigger, the command line does it without loading the file at all — "shasum -a 256 file.iso" on macOS and Linux, or "certutil -hashfile file.iso SHA256" on Windows.
Why is MD5 here at all if it is broken?
Because download pages still publish MD5 checksums by the thousand, and a tool that cannot check them sends you elsewhere. It is included and labelled broken rather than quietly left out. Note that browsers do not provide MD5 — the Web Crypto API deliberately omits the algorithms it considers unsafe — so the MD5 here is implemented in this page's own code, while SHA-1 through SHA-512 come from the browser.