Hash Generator (SHA-256, SHA-1, SHA-512)

Get the SHA-256, SHA-512 or SHA-1 hash of any text as you type.

Hash

Free forever, no sign-up and no limits, and this tool installs on its own so you can keep it on your home screen.

Compute SHA-256, SHA-384, SHA-512, SHA-1 or MD5 hashes of any text or file. Text hashes update as you type; drop a file and all five algorithms are computed at once, at sizes up to about 200 MB. Paste an expected checksum and the tool detects which algorithm it is and gives a plain match or no-match verdict.

How to use it

  1. Paste text, or drop a fileText is rehashed on every keystroke. A file gets all five algorithms at once; anything up to 200 MB works.
  2. Choose an algorithmSHA-256 is the sensible default. SHA-1 and MD5 are offered for checking against legacy checksums, with an honest note on what each is still good for.
  3. Copy, or verifyCopy any hash, or paste the checksum a download page gave you and read the verdict: match or no match, algorithm detected automatically.

What hashes are actually for

A hash answers one question well: has this data changed? Download a file, hash it, compare against the publisher's figure, and a mismatch tells you something is wrong, corruption in transit, or tampering. Because a single altered bit changes the entire output, there is no such thing as a near match.

The same property underpins a great deal of infrastructure. Git names every commit by the hash of its contents. Blockchains chain blocks by hash. Digital signatures sign a hash rather than a whole document, because the hash is small and stands in for the document exactly.

Choosing an algorithm

Use SHA-256 unless you have a specific reason not to. It is secure, fast, and universally supported, which means the system on the other end almost certainly expects it. SHA-384 and SHA-512 produce longer digests and can be quicker on 64-bit processors; pick them when something you are integrating with asks for them.

SHA-1 and MD5 are here for one reason: older systems still publish those checksums, and you occasionally need to verify against one. Both are cryptographically broken and should never be chosen for anything new, which is why each carries its own honesty line in the tool rather than sitting unlabelled next to the sound ones.

Checking a download the honest way

The commonest real task here is verification: a download page publishes a checksum, and you want to know your copy matches. Paste the published value into the verify field and the tool does the fiddly parts for you, it recognises the algorithm from the checksum's length, computes that hash of your file or text, and states the verdict in words: match, or no match. No squinting at 64 hexadecimal characters to spot a difference your eyes will miss.

The password mistake

The most common misuse of a tool like this is hashing passwords with SHA-256 and storing the result. It feels responsible and is not. General-purpose hashes are built to be fast, and speed is precisely what an attacker with a stolen database wants, commodity hardware can test billions of candidate passwords per second against a fast hash.

Password hashing needs the opposite: a function deliberately made slow and memory-hungry, with a unique salt per user so identical passwords do not produce identical hashes. Argon2, scrypt and bcrypt exist for this. If you are storing credentials, reach for one of those, not for this page.

The same code that secures HTTPS

Hashing here uses the cryptography already built into the platform, the same implementation behind an HTTPS connection, rather than a hand-rolled copy of the algorithm. That is why a SHA-256 from this page matches the one your shell or your language runtime produces, digit for digit, on the same input. A hash that disagrees with the next tool along is worse than no hash at all.

Questions people ask

What is a hash?

A fixed-length fingerprint of some data. The same input always gives the same output, but the process cannot be reversed to recover the input, and changing a single character produces a completely different hash. That makes hashes useful for checking that something has not been altered.

Can I get the original text back from a hash?

No. Hashing is one-way by design. For short or common inputs an attacker can guess candidates and hash them until one matches, which is why hashing alone is not enough to protect passwords, but you cannot invert the function itself.

Should I use this to hash passwords?

No. Plain SHA-256 is far too fast, which is exactly wrong for passwords: modern hardware can try billions of guesses per second. Passwords need a deliberately slow algorithm with a per-user salt, such as bcrypt, scrypt or Argon2. Use this tool for integrity checks, not credential storage.

Are SHA-1 and MD5 safe?

Not for security, and both are labelled accordingly in the tool. MD5 collisions have been trivial to produce since 2004, and a practical SHA-1 collision was demonstrated in 2017, meaning two different inputs can be constructed with the same hash. Both remain perfectly fine for spotting accidental corruption, an interrupted download, a bad disk, and useless against anyone hostile. Use them only to match a checksum a legacy system already publishes, never for signatures or passwords.

Why does my hash differ from another tool's?

Almost always a difference in input, not algorithm. A trailing newline, a space, or text saved with Windows line endings will change the hash completely. Files also hash differently from the text they contain. Check the input matches byte for byte before suspecting the algorithm.

Can it hash a file?

Yes. Switch to the file tab, drop the file or browse for it, and every algorithm is computed at once: MD5, SHA-1, SHA-256, SHA-384 and SHA-512. The practical limit is about 200 MB; past that, the page tells you plainly and a checksum tool on your computer is the better answer.

How does verify mode know which algorithm my checksum is?

By its length. Each algorithm produces a fixed-size result: MD5 is 32 hex characters, SHA-1 is 40, SHA-256 is 64, SHA-384 is 96, SHA-512 is 128. The tool measures what you pasted, names the algorithm, and compares it against the matching hash of your text or file. A leading 'sha256:' style prefix is stripped automatically.

What is the difference between a hash and a checksum?

In practice, nothing. A checksum is a hash being used for one particular job, confirming that a file arrived as it left. The word checksum describes the purpose and the word hash describes the function, and both sides only need to run the same algorithm, which is what verify mode works out for you.