Hash Generator (SHA-256, SHA-512)
Calculate SHA-256, SHA-384, SHA-512 and SHA-1 hashes for text or any file, using your browser's built-in cryptography. Paste an expected checksum to confirm a download is intact.
Generate hashes
Web Crypto API · text or files.
Weak SHA-1 is shown for checking older checksums only. It is broken for security uses such as signatures — use SHA-256 or stronger.
Hashes
How to use it
- Type or paste text; all four hashes update as you type. Or click "Hash a file" to hash any file on your device.
- Choose the output format: lowercase hex (most common), uppercase hex or Base64.
- To verify a download, paste the checksum from the publisher into "Compare with an expected hash".
- Copy any hash with the button next to it.
Good to know
- Text is hashed as UTF-8
- The hash is calculated over the UTF-8 bytes of exactly what is in the box, including spaces and line breaks. A trailing newline changes the result, so be careful when comparing with command-line tools.
- Files stay on your device
- Files are read by the browser and hashed locally (up to 200 MB). Nothing is uploaded.
- Why no MD5?
- MD5 is not part of the Web Crypto API and is broken for security use. For checksums, SHA-256 is the modern standard.
Frequently asked questions
What is a hash?
A fixed-length fingerprint of data. The same input always gives the same hash, and changing a single character gives a completely different one, which makes hashes useful for checking that files have not changed.
Can a hash be reversed to get the text back?
No. Hash functions are one-way. Short or common inputs (like simple passwords) can still be guessed by trying many candidates, which is why passwords should be stored with a slow, salted algorithm such as bcrypt or Argon2, not plain SHA-256.
Why is my hash different from the one on my terminal?
Usually because of a newline: echo adds one. Use echo -n "text" | sha256sum, or compare the exact same bytes.
Is SHA-1 safe?
Not for security. Practical collisions exist. It is included only to check older checksums.