Hash Generator — SHA-256, SHA-512 & MD5 Online
Part of Text tools: See all Text tools.
What is Hash Generator?
This free hash generator turns any text into a SHA-256, SHA-384, SHA-512 or MD5 hash, shown as lowercase hexadecimal with a Copy button. The SHA hashes use your browser's built-in Web Crypto feature, and MD5 uses a small JavaScript library, so the text you type is hashed on your device and is not sent to our server. It hashes text, not files.
How to use Hash Generator
- Type or paste your text into the Input text box. Spaces and line breaks are part of the input.
- Choose an algorithm: SHA-256 (the default), SHA-384, SHA-512 or MD5.
- Click Generate Hash. The hex digest appears in the Hash field.
- Click Copy and paste the hash where you need it, for example to compare it with a published value.
Why use this tool?
Hashes let you check that two pieces of text are identical without comparing them character by character, create stable IDs and cache keys, and test code that produces digests. Doing it in the browser means you do not need a terminal, and the text never leaves your device.
Choose the right hash: SHA-256 is a safer default for integrity checks. Use MD5 only when you need compatibility with older systems.
Hashes are fingerprints - if even one character changes, the hash changes too.
What this hash generator does
Paste text, choose an algorithm and click Generate Hash. The tool encodes your text as UTF-8 and runs it through the algorithm you chose. It shows the result as lowercase hexadecimal. SHA-256, SHA-384 and SHA-512 are computed by the browser's built-in Web Crypto feature. MD5 is computed by the blueimp-md5 JavaScript library, which the page loads from a public CDN. Either way, the hashing happens on your device.
You can check the tool against the standard test values. We ran these through it, and they match the published results:
| Input | Algorithm | Hash |
|---|---|---|
abc | SHA-256 | ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad |
abc | MD5 | 900150983cd24fb0d6963f7d28e17f72 |
| (empty) | SHA-256 | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
| (empty) | MD5 | d41d8cd98f00b204e9800998ecf8427e |
What a hash is
A cryptographic hash function takes input of any length and produces a fixed-length fingerprint. The same input always gives the same output. Change one character, even a capital letter or a trailing space, and the output changes completely. You cannot work back from the hash to the input. That makes hashes useful for checking that two things are identical, for building IDs and cache keys from content, and as a building block in signatures and integrity checks.
Choosing an algorithm
- SHA-256 (64 hex characters) is the sensible default. It is widely used for checksums, content addressing and signatures, and it has no known practical collision attacks.
- SHA-384 (96 characters) and SHA-512 (128 characters) belong to the same SHA-2 family, with longer outputs. Use them when a specification asks for them, for example SHA-384 for Subresource Integrity values. The base64 value used there is a different encoding of the same digest.
- MD5 (32 characters) is still used for quick, non-security checks and in older systems. It should not be used where an attacker could benefit from two different inputs with the same hash, because such collisions can be created on purpose.
SHA-1 is not offered. It is deprecated for security use, and SHA-256 is the better choice for new work.
Why your hash might not match
Most “wrong hash” problems come from the input, not the algorithm. Check these in order:
- Trailing newline.
echo abc | sha256sumhashes “abc” plus a line break, which gives a different result from “abc” typed here. Useprintf 'abc'orecho -n abcto compare like for like. - Line endings. Browser text boxes use plain line feeds. Text saved on Windows usually has CRLF endings, so the same visible text hashes differently.
- Hidden spaces and characters. Copying from a PDF or a chat app can add non-breaking spaces or zero-width characters that you cannot see.
- Encoding. This tool hashes UTF-8. A system that hashes Latin-1 or UTF-16 will get a different result for accented letters and emoji.
- Letter case of the output. Hex digests are not case-sensitive.
BA78…andba78…are the same hash, and this tool shows lowercase.
Hashing is not password storage or encryption
A plain SHA-256 or MD5 of a password is a poor way to store it. Those algorithms are built to be fast, so an attacker with a leaked database can test billions of guesses per second. Real systems use a slow, salted password-hashing function such as Argon2, bcrypt or scrypt. Hashing is also different from encryption: encrypted data can be decrypted with a key, and a hash cannot be turned back into the input. If you need a reversible text format, see the Base64 Encoder and Decoder. Remember that Base64 is not secret either.
Checking a downloaded file
This page hashes text only. To check a file you downloaded against the checksum on the publisher's site, use the built-in command for your system. Then paste both values into a text editor to compare them:
- Windows:
certutil -hashfile installer.exe SHA256 - macOS:
shasum -a 256 installer.dmg - Linux:
sha256sum installer.tar.gz
Privacy
The text you hash stays in your browser. SHA hashing uses Web Crypto and MD5 uses a JavaScript function on the page, and neither the input nor the result is sent to our server. Even so, avoid pasting live production secrets into any website. Related tools: the Password Generator makes random passwords, the JSON Formatter tidies API payloads, and the Regex Tester checks hex patterns.
Frequently asked questions
- Which hash algorithms are supported?
- SHA-256, SHA-384, SHA-512 and MD5. SHA-1 is not offered. Output is lowercase hexadecimal: 64 characters for SHA-256, 96 for SHA-384, 128 for SHA-512 and 32 for MD5.
- Can I hash a file to check a download?
- No. This tool hashes text that you type or paste. To check a downloaded file against a published checksum, use your operating system: certutil -hashfile file SHA256 on Windows, shasum -a 256 file on macOS, or sha256sum file on Linux.
- Why does my hash not match the one I expected?
- Hashes change completely if even one character is different. Look for an extra space, a trailing line break, different capital letters, or Windows (CRLF) line endings in the original. A browser text box always uses plain line feeds, so text with CRLF endings hashes differently elsewhere. Also check that you picked the same algorithm.
- Can a hash be reversed or decrypted?
- No. A hash is a one-way fingerprint, not encryption. However, short or common inputs can be guessed by trying many candidates, so a hash does not hide a weak password.
- Should I use MD5 or SHA-256?
- Use SHA-256 unless a system specifically asks for MD5. MD5 is fine for detecting accidental changes, but it is broken for security uses because collisions can be manufactured. For storing passwords, use a slow password-hashing scheme such as Argon2, bcrypt or scrypt, not any of these.
- Is my text sent anywhere?
- No. Hashing runs in your browser using Web Crypto for SHA and a JavaScript library for MD5. The text and the hash are not sent to our server.
Also try
Related tools that work well with this one: