Hash Generator

Get the MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes of any text at once, updated as you type, with a plain note on which ones are still safe for security work.

Updated

Developer ToolsPopular● Free No upload Instant

Loading Hash Generator…

Your browser is preparing the tool. It runs 100% locally.

Quick answer

Type text and the tool shows its MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes side by side in hexadecimal, updating as you type. Hashing is one-way, so you cannot turn a hash back into the text. MD5 and SHA-1 are cryptographically broken and should not be used for security, while the SHA-256 family is fine for integrity checks. None of the five is suitable for storing passwords. Your browser computes all of them.

What the Hash Generator does

Paste or type a string and you get five hashes: a short MD5, a SHA-1, and the longer SHA-256, SHA-384 and SHA-512. Each is a fixed-length hexadecimal fingerprint of your input, and changing one character changes every hash completely.

A hash works as a one-way fingerprint. The same input always gives the same output, but you cannot reverse it to recover the text. That makes hashes useful for checking that data has not changed, comparing files and spotting duplicates. Hiding data is a job for encryption.

How it works

The SHA hashes come from the browser's built-in Web Crypto digest function. MD5 comes from a small bundled implementation, because browsers no longer offer MD5 natively. Your text is read as UTF-8 bytes first, so accented and non-Latin characters hash consistently.

Each algorithm produces a fixed length whatever the input size: MD5 is 32 hex digits, SHA-1 is 40, SHA-256 is 64, SHA-384 is 96 and SHA-512 is 128. Identical input always yields identical hashes, which is what lets two people compare a hash to confirm they hold the same data.

Generation algorithm

  1. Read the text as UTF-8. Convert your input to UTF-8 bytes so every character hashes consistently.
  2. Compute the SHA hashes. Use the browser's Web Crypto digest for SHA-1, SHA-256, SHA-384 and SHA-512.
  3. Compute MD5. Run the bundled MD5 implementation, since browsers do not provide it.
  4. Show as hexadecimal. Display each fixed-length hash as lowercase hex, updating as you type.

Hash lengths (hex digits)

MD5 → 32 SHA-1 → 40 SHA-256 → 64 SHA-384 → 96 SHA-512 → 128

Each algorithm always outputs the same length, whatever the input size. The same input always gives the same hash.

Privacy

Your browser does all the hashing and the text you type is never uploaded, so you can hash sensitive values without them leaving your device.

A hash cannot be reversed, but it does not keep a secret safe either. Identical inputs produce identical hashes, so a short or common input can be matched against precomputed tables. A plain hash of a password or secret gives it no protection.

Technical details

AlgorithmsMD5, SHA-1, SHA-256, SHA-384, SHA-512
SHA methodWeb Crypto (browser built-in)
MD5 methodbundled implementation
Inputread as UTF-8
Outputlowercase hexadecimal, fixed length
Directionone-way (cannot be reversed)
Where it runsIn your browser; the text is not sent

Standards and references

  • MD5 and SHA-1 are broken: practical collision attacks exist (MD5 since the mid-2000s, SHA-1 since the 2017 SHAttered attack), so neither is safe for signatures or security. Both still work as non-security checksums.
  • SHA-2 family: SHA-256, SHA-384 and SHA-512 have no known practical attacks and are the standard choice for integrity verification.
  • Not for passwords: all five are fast, general-purpose hashes. Storing passwords needs a slow, salted password hash such as bcrypt, scrypt or Argon2.

Accuracy and limits

MD5 and SHA-1 are cryptographically broken. Attackers can craft two different inputs with the same MD5 or SHA-1 hash, so do not use them for digital signatures, certificates or anything else where security matters. They are still fine for a quick checksum or a cache key.

Do not use any of these to store passwords. They are fast by design, so a leaked database of fast hashes can be cracked at billions of guesses per second. Passwords need a deliberately slow, salted algorithm such as bcrypt, scrypt or Argon2.

Hashing is not encryption. There is no key and no way back from a hash to the text. If you need to recover the original, you need encryption.

These are plain hashes, without a key (HMAC) or a salt. To verify that a message came from a known party you would use HMAC, and for passwords you would add a unique salt. This tool gives the raw digest only.

The result depends on the exact input. Even an invisible difference, such as a trailing space or a different line ending, changes every hash. That makes tampering obvious, and it also means two inputs must match byte for byte to give the same hash.

Real-world uses

File and data integrity

Compare a hash to confirm that data arrived or copied without changing.

Deduplication

Use a hash as a fingerprint to spot identical content.

Cache keys

Turn a long input into a fixed-length key for caching or lookup.

Checksums

Check a value against a published MD5 or SHA checksum.

When it fits, and when it doesn't

Good for

  • Integrity and checksum verification
  • Fingerprinting or deduplicating data
  • Generating cache or lookup keys
  • Comparing SHA-256 checksums

Not the best choice for

  • Storing or verifying passwords
  • Security uses of MD5 or SHA-1
  • Hiding data (that is encryption)
  • Authenticating a message sender (use HMAC)

For storing passwords, use bcrypt, scrypt or Argon2 with a unique salt. To hide data you will need to read again, use encryption. To verify who sent a message, use an HMAC with a shared key.

Frequently asked questions

Can I reverse a hash to get the text back?
No. Hashing is one-way by design, with no key and no reverse function. When a website shows the original text for a hash, it found it in a precomputed table; it did not reverse the maths.
Are MD5 and SHA-1 safe to use?
Not for security. Both are cryptographically broken, and researchers can produce two different inputs with the same hash. They are fine as plain checksums or cache keys, but never for signatures, certificates or other security work.
Which hash should I use for integrity?
SHA-256 is the usual choice. It has no known practical attacks and is widely supported. SHA-384 and SHA-512 give a longer digest if you want one.
Can I hash a password with this?
You can compute the hash, but do not store passwords this way. These hashes are fast, so a leaked database can be cracked quickly. Passwords need a slow, salted algorithm like bcrypt or Argon2.
Is hashing the same as encryption?
No. Encryption can be reversed with a key, while a hash is a one-way fingerprint with no key. Use encryption to protect data you need to read again.
Why does the hash change completely when I edit one character?
A good hash function spreads any change across the whole output, so a one-character edit gives a totally different hash. That is why hashes are good at revealing tampering.
Why are there five different hashes?
MD5 and SHA-1 are there for older checksums you may need to match, and SHA-256, SHA-384 and SHA-512 for secure integrity checks.
Does the same text always give the same hash?
Yes. Identical input always produces identical output, which is what lets two people compare hashes to confirm they hold the same data.
Why is the input read as UTF-8?
So accented and non-Latin characters hash the same way everywhere. Hashing the bytes of one consistent encoding means the same text gives the same hash on any system.
What is HMAC, and does this do it?
HMAC is a keyed hash that proves a message came from someone who knows a shared secret. This tool produces plain hashes only, so use a dedicated HMAC tool for that.
Is my text uploaded?
No. Your browser computes every hash and sends the text nowhere.
How long is each hash?
Fixed lengths in hex digits: MD5 is 32, SHA-1 is 40, SHA-256 is 64, SHA-384 is 96 and SHA-512 is 128, however long the input is.

References

MD5 comes from a bundled script and SHA-1/256/384/512 from Web Crypto, all run on your UTF-8 text in the browser. MD5 and SHA-1 are broken for security, and none of these fast hashes should store passwords (use bcrypt, scrypt or Argon2).

PopularHot

JSON Formatter

Paste messy or minified JSON and get it back pretty-printed with 2-space indentation. The same step tells you whether the JSON is valid.

DeveloperOpen Tool
Popular

Base64 Encoder

Encode any text to standard Base64 in your browser, emoji and accented letters included.

DeveloperOpen Tool
Popular

UUID Generator

Generate up to 500 random version 4 UUIDs at once, the 128-bit identifiers used for database keys, from your browser's secure random generator.

DeveloperOpen Tool

Base64 Decoder

Decode Base64 back to readable text in your browser, Unicode included, and get a plain error message when the input is broken.

DeveloperOpen Tool

URL Encoder

Percent-encode a value so it can sit safely inside a URL. Spaces, ampersands, slashes and other special characters become %-codes, using the browser's encodeURIComponent.

DeveloperOpen Tool

URL Decoder

Turn percent-encoded text back into readable characters: %20 becomes a space and %26 an ampersand. It uses the browser's decodeURIComponent.

DeveloperOpen Tool

Back to the Hash Generator

Generate as many as you need at the top of the page. It runs on this device and needs no account.