JSON Formatter
Paste messy or minified JSON and get it back pretty-printed with 2-space indentation. The same step tells you whether the JSON is valid.
Get the MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes of any text at once, updated as you type, with a plain note on which ones are still safe for security work.
Updated
Your browser is preparing the tool. It runs 100% locally.
Type text and the tool shows its MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes side by side in hexadecimal, updating as you type. Hashing is one-way, so you cannot turn a hash back into the text. MD5 and SHA-1 are cryptographically broken and should not be used for security, while the SHA-256 family is fine for integrity checks. None of the five is suitable for storing passwords. Your browser computes all of them.
Paste or type a string and you get five hashes: a short MD5, a SHA-1, and the longer SHA-256, SHA-384 and SHA-512. Each is a fixed-length hexadecimal fingerprint of your input, and changing one character changes every hash completely.
A hash works as a one-way fingerprint. The same input always gives the same output, but you cannot reverse it to recover the text. That makes hashes useful for checking that data has not changed, comparing files and spotting duplicates. Hiding data is a job for encryption.
The SHA hashes come from the browser's built-in Web Crypto digest function. MD5 comes from a small bundled implementation, because browsers no longer offer MD5 natively. Your text is read as UTF-8 bytes first, so accented and non-Latin characters hash consistently.
Each algorithm produces a fixed length whatever the input size: MD5 is 32 hex digits, SHA-1 is 40, SHA-256 is 64, SHA-384 is 96 and SHA-512 is 128. Identical input always yields identical hashes, which is what lets two people compare a hash to confirm they hold the same data.
MD5 → 32
SHA-1 → 40
SHA-256 → 64
SHA-384 → 96
SHA-512 → 128Each algorithm always outputs the same length, whatever the input size. The same input always gives the same hash.
Your browser does all the hashing and the text you type is never uploaded, so you can hash sensitive values without them leaving your device.
A hash cannot be reversed, but it does not keep a secret safe either. Identical inputs produce identical hashes, so a short or common input can be matched against precomputed tables. A plain hash of a password or secret gives it no protection.
| Algorithms | MD5, SHA-1, SHA-256, SHA-384, SHA-512 |
|---|---|
| SHA method | Web Crypto (browser built-in) |
| MD5 method | bundled implementation |
| Input | read as UTF-8 |
| Output | lowercase hexadecimal, fixed length |
| Direction | one-way (cannot be reversed) |
| Where it runs | In your browser; the text is not sent |
MD5 and SHA-1 are cryptographically broken. Attackers can craft two different inputs with the same MD5 or SHA-1 hash, so do not use them for digital signatures, certificates or anything else where security matters. They are still fine for a quick checksum or a cache key.
Do not use any of these to store passwords. They are fast by design, so a leaked database of fast hashes can be cracked at billions of guesses per second. Passwords need a deliberately slow, salted algorithm such as bcrypt, scrypt or Argon2.
Hashing is not encryption. There is no key and no way back from a hash to the text. If you need to recover the original, you need encryption.
These are plain hashes, without a key (HMAC) or a salt. To verify that a message came from a known party you would use HMAC, and for passwords you would add a unique salt. This tool gives the raw digest only.
The result depends on the exact input. Even an invisible difference, such as a trailing space or a different line ending, changes every hash. That makes tampering obvious, and it also means two inputs must match byte for byte to give the same hash.
Compare a hash to confirm that data arrived or copied without changing.
Use a hash as a fingerprint to spot identical content.
Turn a long input into a fixed-length key for caching or lookup.
Check a value against a published MD5 or SHA checksum.
For storing passwords, use bcrypt, scrypt or Argon2 with a unique salt. To hide data you will need to read again, use encryption. To verify who sent a message, use an HMAC with a shared key.
MD5 comes from a bundled script and SHA-1/256/384/512 from Web Crypto, all run on your UTF-8 text in the browser. MD5 and SHA-1 are broken for security, and none of these fast hashes should store passwords (use bcrypt, scrypt or Argon2).
Paste messy or minified JSON and get it back pretty-printed with 2-space indentation. The same step tells you whether the JSON is valid.
Encode any text to standard Base64 in your browser, emoji and accented letters included.
Generate up to 500 random version 4 UUIDs at once, the 128-bit identifiers used for database keys, from your browser's secure random generator.
Decode Base64 back to readable text in your browser, Unicode included, and get a plain error message when the input is broken.
Percent-encode a value so it can sit safely inside a URL. Spaces, ampersands, slashes and other special characters become %-codes, using the browser's encodeURIComponent.
Turn percent-encoded text back into readable characters: %20 becomes a space and %26 an ampersand. It uses the browser's decodeURIComponent.
Generate as many as you need at the top of the page. It runs on this device and needs no account.